File: //usr/local/apache/error_log
[Mon Jun 15 20:14:34.918269 2026] [lsapi:notice] [pid 94178:tid 94178] mod_lsapi: version 1.1-92
[Mon Jun 15 20:14:34.924107 2026] [:notice] [pid 50992:tid 50992] [host root@sh008.webhostingservices.com] mod_lsapi: Selfstarter 50992 started
[Mon Jun 15 20:14:34.934753 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: weighdesk.iglitztech.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:34.938554 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: thirdframestrategy.iglitztech.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:34.939485 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: teammint-in.iglitztech.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:34.940065 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: swachairfilters.iglitztech.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:34.940868 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: solispowertech.iglitztech.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:34.942643 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: psapolycraft.iglitztech.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:34.943336 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: perurlakeforum.iglitztech.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:34.944721 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: kielmarketing-in.iglitztech.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:34.945280 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: jsmyth.iglitztech.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:34.947279 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: intellectfaidei.iglitztech.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:34.947927 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: indusfinance-in.iglitztech.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:34.951595 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: eternalsafety-in.iglitztech.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:34.953727 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: banacombaitea.iglitztech.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:34.956082 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: amithengg.iglitztech.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:34.956906 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: shreeharipuri.ctslserver.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:34.957523 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: royalgalaxyhomes.ctslserver.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:34.958573 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: justverified-in.ctslserver.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:34.959168 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: jagannathhospital.ctslserver.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:34.959685 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: indusgeostones.ctslserver.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:34.960276 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: deviansclassesjajpur-in.ctslserver.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:34.961120 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: credaibhubaneswar.ctslserver.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:34.961503 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: ad9sports.ctslserver.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:34.962027 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: thedutchunclepizzeria.littletolarge.in:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:34.962782 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: yourstoreaddons.fpc.pto.mybluehostin.me:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:34.963558 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: weblogiclabs.fpc.pto.mybluehostin.me:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:34.963931 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: trivenistrainers.fpc.pto.mybluehostin.me:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:34.965210 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: symcon-in.fpc.pto.mybluehostin.me:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:34.966562 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: shrinathdentalahmedabad.fpc.pto.mybluehostin.me:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:34.967053 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: owigifilms.fpc.pto.mybluehostin.me:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:34.968040 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: mindbalanceapp.fpc.pto.mybluehostin.me:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:34.968378 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: learn-and-share-in.fpc.pto.mybluehostin.me:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:34.969492 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: freepik-online.fpc.pto.mybluehostin.me:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:34.970690 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: findbestbuys-in.fpc.pto.mybluehostin.me:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:34.973097 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: aroraandjoshi.fpc.pto.mybluehostin.me:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:34.975069 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: traderstraders-in.techcospace.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:34.976396 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: ralphagro.com.techcospace.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:34.977508 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: mindheartequation.techcospace.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:34.979494 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: ayusiddha.techcospace.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:34.991649 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: vijaytmt-com.oforornament.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:34.992036 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: dinairon.oforornament.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:34.996655 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: dodifferent-co-in.auromirasolutions.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.016247 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: sustainableprojects.abhijeetshirke.in:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.017247 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: spaceparivar.biocarelife.in:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.018274 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: railinfra.abhijeetshirke.in:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.019940 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: majividyarthikes.biocarelife.in:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.020298 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: maapanchadevistonehosp.biocarelife.in:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.023478 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: biomass2biooil.biocarelife.in:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.023795 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: biofuel.biocarelife.in:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.024481 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: atharvacomputers-org.biocarelife.in:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.025215 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: anirudhhashirke.in.biocarelife.in:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.026221 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: abhijeetshirke.biocarelife.in:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.026948 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: tec2art.7art.ae:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.027424 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: tec2art-ae.7art.ae:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.027901 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: mdxhassan.7art.ae:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.030734 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: 7artfashion.7art.ae:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.041030 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: vijayaminerals.auromirasolutions.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.041556 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: theindianyarn.auromirasolutions.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.042028 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: thecoimbatorepharmacy-in.auromirasolutions.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.042514 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: srttextilespares.auromirasolutions.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.043022 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: sreegeeconsultant.auromirasolutions.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.043510 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: shrisaibuilders-co-in.auromirasolutions.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.044007 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: samicars.auromirasolutions.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.044511 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: sabaarthouse.auromirasolutions.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.044995 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: photographytipstricks.auromirasolutions.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.045501 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: mycoimbatore.auromirasolutions.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.046007 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: merakitechnocrats.auromirasolutions.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.046480 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: merakicncmachines.auromirasolutions.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.046960 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: mantrafibertec.auromirasolutions.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.047457 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: kovaibiriyanihotel.auromirasolutions.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.047957 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: kcrfoundation.auromirasolutions.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.048433 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: hotelgrandpalacecbe.auromirasolutions.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.048927 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: homampoojas.auromirasolutions.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.049420 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: hasinitravels-in.auromirasolutions.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.049898 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: geethahotels.auromirasolutions.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.050377 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: eniaashridigitals.auromirasolutions.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.050914 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: eltecmoldbase.auromirasolutions.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.051396 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: eltecengineering-net.auromirasolutions.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.051878 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: ebtiplc-in.auromirasolutions.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.052369 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: dodifferent-in.auromirasolutions.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.052882 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: cripumpshebron.auromirasolutions.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.053383 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: coimbatoretaxibooking-in.auromirasolutions.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.053861 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: bvmachines-in.auromirasolutions.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.054317 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: bharathanceramics.auromirasolutions.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.054787 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: beztkulfis.auromirasolutions.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.055281 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: auromirasolutions-in.auromirasolutions.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.055780 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: assetplusproperty.auromirasolutions.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.056246 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: arasansoap.auromirasolutions.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.056742 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: arasanresidency.auromirasolutions.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.057235 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: arasanpaints.auromirasolutions.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.057735 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: arasanmachinetools.auromirasolutions.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.058235 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: aloesh.auromirasolutions.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.058723 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: alayatra.auromirasolutions.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.059192 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: adityahotel-co-in.auromirasolutions.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.059699 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: magnusedge.mrsinghadvice.in:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.064425 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: jfoods.co.in:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.069999 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: theomnibliss.sabloknews.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.085400 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: hanumanproperties-in.tnd.nwp.mybluehostin.me:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.091616 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: dreambasketstore.mrsinghadvice.in:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.099891 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: linkfro.zeropointseo.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.100212 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: travelallow.zeropointseo.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.100689 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: seolinkcity.zeropointseo.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.101155 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: search4online.zeropointseo.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.101653 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: blackbee-digital.zeropointseo.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.103672 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: zecaado-asia.zecaado.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.118886 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: vizagaerolabs.beincareer.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.119916 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: singamfence-in.beincareer.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.120736 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: archiesdressrental-in.whataboutindia.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.133312 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: kitesman.webapexindia.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.133816 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: gladies-in.webapexindia.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.134305 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: fatehgarhsahibdba.webapexindia.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.135265 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: accountsclasses-in.watchallwrestling.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.135736 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: educationtime-co-in.watchallwrestling.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.139990 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: weedtale.buylinks.site:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.140494 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: mapcanna.buylinks.site:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.141011 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: leafpuffs.buylinks.site:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.141521 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: leafsdiary.buylinks.site:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.142011 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: healtyhemp.buylinks.site:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.142499 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: thecbdblogs.buylinks.site:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.142958 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: cbdmap-info.buylinks.site:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.143432 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: the-paystubs.buylinks.site:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.143999 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: mycbdjournal.buylinks.site:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.144537 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: procbdlisting.buylinks.site:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.145079 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: outreachmycbd.buylinks.site:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.145567 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: epaystubs-net.buylinks.site:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.146081 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: mjlistings-org.buylinks.site:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.146628 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: medprocannabis.buylinks.site:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.147197 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: hemppluscbdoil.buylinks.site:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.147706 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: growmarijuanas.buylinks.site:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.148221 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: benifitscbdoil.buylinks.site:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.148783 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: thinkmariajuana.buylinks.site:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.149317 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: healthyhempnews.buylinks.site:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.150319 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: cbdbusinesslist.buylinks.site:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.150803 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: file1099miscform.buylinks.site:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.151271 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: marijuanamoment-org.buylinks.site:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.151763 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: invoicegenerators-net.buylinks.site:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.152226 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: utilitybillgenerator-net.buylinks.site:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.152802 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: utilitybillgenerator-info.buylinks.site:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.153284 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: shrirampackingindustries-in.buylinks.site:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.153787 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: onlinereputationmanagement-agency.buylinks.site:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.167150 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: dmaaya.ubb.mbh.mybluehostin.me:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.168061 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: get16-in.ubb.mbh.mybluehostin.me:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.171657 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: offically-in.ubb.mbh.mybluehostin.me:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.171981 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: nallavaimattum.ubb.mbh.mybluehostin.me:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.175176 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: punybuny.dtptips.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.175654 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: moviezshow.com.dtptips.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.181039 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: sdsolai.theresultscenter.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.181504 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: rkhomes.theresultscenter.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.181975 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: vpioneer.theresultscenter.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.182933 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: utkarsh30.theresultscenter.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.183875 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: vdreamsllc.theresultscenter.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.184334 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: sriramsidd.theresultscenter.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.184813 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: kvscharity.theresultscenter.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.185274 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: hargunagro.theresultscenter.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.185771 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: ahshavtech.theresultscenter.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.186239 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: divaempower.theresultscenter.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.186784 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: occhieyewear.theresultscenter.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.187259 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: mamtasinghco.theresultscenter.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.188223 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: findsmart-in.theresultscenter.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.188729 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: careagritech.theresultscenter.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.189247 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: hydurbanrealty.theresultscenter.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.189745 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: healingessence.theresultscenter.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.190262 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: sriramschool-in.theresultscenter.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.191252 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: extrovertevents.theresultscenter.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.191746 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: discoveryourjob.theresultscenter.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.192784 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: chandrasplayschool.theresultscenter.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.193255 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: sriramschoolnizampet-in.theresultscenter.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.193726 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: localgoan.thejunketjourneys.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.200700 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: komalcaterers.sunglobalapparels.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.213601 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: riddheecon.kakhag.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.213947 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: thalakbatmi.kakhag.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.214427 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: kakhaga-net.kakhag.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.214898 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: unitechgauges.kakhag.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.215369 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: network100-in.kakhag.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.215829 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: gokrupa-co-in.kakhag.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.216744 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: money-solutions-in.kakhag.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.217233 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: bhuvancreativities.kakhag.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.217756 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: aestheticinterio-net.kakhag.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.223770 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: mikaan-in.shrikamal.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.224270 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: mikaan-co.shrikamal.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.225813 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: meet2tech-in.shrikamal.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.226489 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: sanskratshlok.shrikamal.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.227495 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: vchateschool-in.shrikamal.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.227860 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: aviationiaindia.shrikamal.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.228346 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: sherviaviationia.shrikamal.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.228846 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: newsmaharashtra1.shrikamal.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.229217 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: skylarkaviation-in.shrikamal.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.229709 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: kisanaworldtourism.shrikamal.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.230182 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: chateschoolkaij-in.shrikamal.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.230552 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: pavanrajeenglishschool.shrikamal.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.230903 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: pdscambridgeenglishschool.shrikamal.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.231547 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: zignflix.scalgo.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.244796 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: manilthas.rotarydistrict3190.org:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.245584 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: panchavakthram.rotarydistrict3190.org:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.245906 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: thenextlesson-in.rotarydistrict3190.org:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.246403 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: organicbigha.rkumardigital.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.246741 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: jaivikkisansarthi.rkumardigital.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.247243 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: yadupatiorganicindia.rkumardigital.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.249383 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: bloggermint.franklinmanuel.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.249867 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: sahilpatro.rahulpatro.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.250332 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: archresource-co.rahulpatro.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.250795 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: angelonefinance-net.radhikaservicesindia.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.251281 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: persistentgrowthfund.radhikaservicesindia.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.251632 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: jenordesignsllc-info.radhikaservicesindia.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.257082 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: medicalrecordsreform.medicalrecordsreform.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.259728 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: theexpressarticle.protechnoid.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.262865 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: viayaam.oforornament.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.263189 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: sayojit.oforornament.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.264236 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: cricketrings.experienceleaf.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.269862 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: kbut-in.ohocorea.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.270342 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: ohosys-in.ohocorea.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.270799 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: daesang-in.ohocorea.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.271272 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: rakgranites.ohocorea.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.271745 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: ca-group-in.ohocorea.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.295365 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: uxbird.nutsforest.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.297580 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: sattrexcapital.networthsolutionsgroup.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.297931 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: gogurueducationhub.networthsolutionsgroup.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.298298 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: networthsolutions-in.networthsolutionsgroup.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.299584 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: pressify.cncstones.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.300213 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: astonetech.cncstones.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.300697 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: anandvatica.cncstones.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.304798 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: onionbell.mtabassum.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.305135 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: editonmedia.mtabassum.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.305951 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: spinyy.mrsinghadvice.in:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.306436 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: zomawin.mrsinghadvice.in:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.306905 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: crcbold.mrsinghadvice.in:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.307375 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: robre-in.mrsinghadvice.in:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.307844 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: levitadz.mrsinghadvice.in:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.308834 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: legioads.mrsinghadvice.in:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.309860 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: virtusads.mrsinghadvice.in:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.310696 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: adslither.mrsinghadvice.in:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.311175 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: grovia-net.mrsinghadvice.in:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.312122 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: fondxchange.mrsinghadvice.in:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.312602 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: tripzotravel.mrsinghadvice.in:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.313070 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: spyaddisplay.mrsinghadvice.in:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.313869 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: debtshelpers.mrsinghadvice.in:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.314343 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: hpsloyalty-in.mrsinghadvice.in:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.314836 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: geekstechtips.mrsinghadvice.in:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.315316 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: easemyflights.mrsinghadvice.in:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.316661 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: insurance-scout.mrsinghadvice.in:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.316998 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: dreamspaceshopp.mrsinghadvice.in:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.317476 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: healthyandfitter.mrsinghadvice.in:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.318249 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: lifeinsuranceshops.mrsinghadvice.in:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.318624 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: debtfriendlyrelief.mrsinghadvice.in:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.319443 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: autoquoteguide-net.mrsinghadvice.in:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.320232 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: autofriendlyinsurance.mrsinghadvice.in:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.320713 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: thedailylifeessentials.mrsinghadvice.in:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.321045 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: pricedropautoinsurance.mrsinghadvice.in:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.321687 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: lifeinsurancesavings-net.mrsinghadvice.in:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.345779 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: metlamind.truezor.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.346423 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: trustindsh.truezor.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.347072 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: sunbowfashions.truezor.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.347727 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: sunairfreight-in.truezor.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.348052 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: shriganapathisourses.truezor.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.359426 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: toolx-in.mazacart.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.359925 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: nesty-in.mazacart.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.360409 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: botiq-in.mazacart.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.360880 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: crispyway.mazacart.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.361371 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: tcspune-in.mazacart.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.361871 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: aiotool-in.mazacart.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.362319 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: medxtech-in.mazacart.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.362816 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: mazacart-in.mazacart.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.363307 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: everyads-in.mazacart.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.363782 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: ignitehub-in.mazacart.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.364289 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: fastshare-in.mazacart.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.364810 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: buyndrive-in.mazacart.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.365294 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: vizitcardz-in.mazacart.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.365801 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: rvfinserve-in.mazacart.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.366289 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: incredbill-in.mazacart.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.366782 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: schoolytics-in.mazacart.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.370295 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: pallavicomputers.madakasira.in:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.373903 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: garudaworld-in.lrf.cox.mybluehostin.me:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.375282 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: garudaproductions.lrf.cox.mybluehostin.me:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.378551 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: qeevitech.alphageekz.info:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.383789 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: alphasamples-online.alphageekz.info:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.384588 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: adzygo.sliverlightagency.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.385058 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: autoflos.sliverlightagency.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.385444 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: iserif.lemmah.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.385821 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: bugzilla.lemmah.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.386944 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: alstrenengineering.lemmah.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.388802 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: ruchini.kthemani.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.390838 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: hemani-finance.kthemani.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.391339 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: sciencecenterrajkot-org.kthemani.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.437786 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: burgerking-menu.itj.bth.mybluehostin.me:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.444878 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: forms.legalaspire.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.450570 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: allknown-in.intrepid-marketing.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.452552 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: convlyze.intermartindia.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.455183 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: tristarmusic.intermartindia.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.458129 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: gizmobaba-com.intermartindia.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.460747 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: fifthestate-agency.hxu.iit.mybluehostin.me:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.463035 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: hydaltraders.bestzcloudhosting.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.464151 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: marshitechindia.bestzcloudhosting.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.465308 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: smartchoicereviews.bestzcloudhosting.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.465810 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: rjinspirationhands.bestzcloudhosting.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.466560 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: srinivasgorthyandco.bestzcloudhosting.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.468987 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: ushealthcarecenter.happiestwaves.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.471214 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: vanimahal.getitquic.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.471712 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: themadart.getitquic.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.472179 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: swayamadds.getitquic.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.473174 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: lcfc-org-in.getitquic.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.473649 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: opexcel-co-in.getitquic.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.473974 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: legalworldgroup.getitquic.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.474454 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: ssaquatechnologies.getitquic.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.474938 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: sribalajishuttering.getitquic.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.475426 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: sribalajicenterring.getitquic.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.475909 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: sribalajiconstructions.getitquic.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.476383 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: sribalajiindustries-co-in.getitquic.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.486267 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: dyflow.figoindia.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.486807 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: cravatex.figoindia.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.487334 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: rahejabay.figoindia.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.487914 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: hificlean.figoindia.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.488429 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: tezzoindia.figoindia.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.488933 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: muktiindia.figoindia.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.489473 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: celltone21.figoindia.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.489995 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: sam-andy-in.figoindia.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.490507 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: neptuneinfo.figoindia.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.491021 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: galaxyshows.figoindia.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.491533 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: deepagahlot.figoindia.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.492057 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: comluxindia.figoindia.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.492571 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: alkemidecor.figoindia.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.493048 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: hksrealty-in.figoindia.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.493536 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: figoindia-in.figoindia.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.494053 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: lsrsaw-edu-in.figoindia.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.494595 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: figoindia-net.figoindia.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.495096 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: dnavinchandra.figoindia.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.495575 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: harishperfumes.figoindia.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.496035 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: 5thquarter-net.figoindia.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.496529 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: simandharherbal.figoindia.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.497038 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: connekthomes-in.figoindia.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.497542 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: rushabhaluminium.figoindia.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.498082 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: estore-neptuneinfo.figoindia.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.498687 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: parshwanathagritech.figoindia.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.499186 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: livingimpressions-in.figoindia.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.499726 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: demo9-5thquarter-net.figoindia.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.500250 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: demo8-5thquarter-net.figoindia.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.500796 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: demo3-5thquarter-net.figoindia.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.501310 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: demo2-5thquarter-net.figoindia.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.501846 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: demo20-5thquarter-net.figoindia.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.502374 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: demo13-5thquarter-net.figoindia.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.502892 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: demo12-5thquarter-net.figoindia.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.503374 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: demo10-5thquarter-net.figoindia.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.503903 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: restofmaharashtraairtel-in.figoindia.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.511185 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: frienect-net.fatimalegaldesk.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.512232 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: basrifatimafoundation-org.fatimalegaldesk.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.520971 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: jui-usa-us.eskillgrow.us:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.522809 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: wefri-edu-us.eskillgrow.us:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.523309 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: convertease-us.eskillgrow.us:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.523794 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: crownofgames-us.eskillgrow.us:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.525223 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: talentforge-hr-org.eskillgrow.us:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.525558 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: nextgenuniversity-us.eskillgrow.us:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.526034 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: mypropertyglobal-org.eskillgrow.us:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.526511 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: doctoratepublications.eskillgrow.us:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.527002 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: nextgenuniversity-edu-us.eskillgrow.us:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.538507 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: uxdco.dravinash.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.539439 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: webfx-me.dravinash.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.539918 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: vrsclick.dravinash.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.540390 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: skrajula.dravinash.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.541361 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: sasclinical.dravinash.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.543308 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: datatrek-org.dravinash.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.543824 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: brainstrom-org.dravinash.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.545790 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: itconnectservices.dravinash.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.548373 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: pagetrial.dabariya.in:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.548696 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: haemovigil.dabariya.in:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.549021 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: eridenindia.dabariya.in:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.549361 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: jgmtrusterp-in.dabariya.in:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.551623 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: teacherrk.businessstudies365.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.552100 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: thevoiceofrk.businessstudies365.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.552573 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: ayuryogaheal.bridgegaptraders.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.553053 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: bridgegap-co-in.bridgegaptraders.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.553381 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: ms1.brain-quantum.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.555214 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: egbnew.brain-quantum.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.572729 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: indusjs.anuvacrest.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.573495 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: indusjsinfotech.anuvacrest.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.575584 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: bengalcomputers.amazingsparks.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.581481 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: fogalo-in.dopetechsolution.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.587385 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: zecaado.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.599049 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: ubb.mbh.mybluehostin.me:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.601715 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: dtptips.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.618642 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: scalgo.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.659700 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: truezor.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.665437 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: kridha.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.679041 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: gleegal.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.679905 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: girishpaniker.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.684136 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: themasklab.in:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.690625 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: enenni.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.716690 2026] [ssl:warn] [pid 94178:tid 94178] AH01909: localhost:8443:0 server certificate does NOT include an ID which matches the server name
[Mon Jun 15 20:14:35.734289 2026] [qos:notice] [pid 94178:tid 94178] mod_qos(007): calculated MaxClients/MaxRequestWorkers (max connections): 6144, applied limit: 2048 (QS_MaxClients)
[Mon Jun 15 20:14:35.993741 2026] [http2:info] [pid 94178:tid 94178] AH03090: mod_http2 (v2.0.42, feats=CHPRIO+SHA256+INVHD+DWINS, nghttp2 1.69.0), initializing...
[Mon Jun 15 20:14:35.999696 2026] [mpm_event:notice] [pid 94178:tid 94178] AH00489: Apache/2.4.68 (cPanel) OpenSSL/3.5.5 Apache mod_qos/11.76 mod_bwlimited/1.4 mod_fcgid/2.3.9 mod_rbld2.0 configured -- resuming normal operations
[Mon Jun 15 20:14:35.999709 2026] [core:notice] [pid 94178:tid 94178] AH00094: Command line: '/usr/sbin/httpd'
[Mon Jun 15 20:14:37.072052 2026] [http2:info] [pid 51003:tid 51003] h2_workers: created with min=128 max=192 idle_ms=600000
[Mon Jun 15 20:14:37.095346 2026] [security2:error] [pid 51003:tid 51137] [client 143.244.57.88:38708] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "rkfreshmart.net"] [uri "/wp-admin/network/"] [unique_id "ajCxjcpsKyvb75pkSvZzSgAAAZM"]
[Mon Jun 15 20:14:37.127948 2026] [security2:error] [pid 51003:tid 51006] [remote 57.141.14.73:33024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.14.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wilsonoverseas.com"] [uri "/items/E571958389"] [unique_id "ajCxjcpsKyvb75pkSvZzUAAB2wI"]
[Mon Jun 15 20:14:37.151444 2026] [security2:error] [pid 51003:tid 51048] [remote 74.7.227.173:48972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.rentswale.ehx.czu.mybluehostin.me"] [uri "/fonts/images/js/images/admin/uploads/source/css/img/subcategory.php"] [unique_id "ajCxjcpsKyvb75pkSvZzfwAB5yw"], referer: https://www.rentswale.ehx.czu.mybluehostin.me/fonts/images/js/images/admin/uploads/source/css/img/upi.png
[Mon Jun 15 20:14:37.181480 2026] [core:error] [pid 51003:tid 51056] [remote 2a03:2880:f800:11:::0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jun 15 20:14:37.181504 2026] [core:error] [pid 51003:tid 51056] [remote 2a03:2880:f800:11:::0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jun 15 20:14:37.276789 2026] [security2:error] [pid 51003:tid 51061] [remote 104.155.29.73:56493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.29.155.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hydlab.co.in"] [uri "/wp-login.php"] [unique_id "ajCxjcpsKyvb75pkSvZzqQAB4zk"]
[Mon Jun 15 20:14:37.279433 2026] [security2:error] [pid 51003:tid 51063] [remote 194.32.155.65:52784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.155.32.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "enterkitgames.com"] [uri "/wp-login.php"] [unique_id "ajCxjcpsKyvb75pkSvZzrAABwzs"]
[Mon Jun 15 20:14:37.297432 2026] [security2:error] [pid 51003:tid 51206] [client 159.65.5.161:52214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.5.65.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lotuswarrior.in"] [uri "/administrator/"] [unique_id "ajCxjcpsKyvb75pkSvZzsgAAAdg"]
[Mon Jun 15 20:14:37.298475 2026] [security2:error] [pid 51003:tid 51223] [client 57.141.14.86:56272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCxjcpsKyvb75pkSvZzYAAB6Q8"]
[Mon Jun 15 20:14:37.310185 2026] [autoindex:error] [pid 51003:tid 51064] [remote 51.89.39.37:53843] AH01276: Cannot serve directory /home2/sajeevan/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:14:37.318638 2026] [security2:error] [pid 51003:tid 51186] [client 57.141.14.110:42600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCxjcpsKyvb75pkSvZzYQABxAo"]
[Mon Jun 15 20:14:37.351468 2026] [security2:error] [pid 51003:tid 51155] [client 57.141.14.89:25722] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCxjcpsKyvb75pkSvZzYgABpQU"]
[Mon Jun 15 20:14:37.361429 2026] [security2:error] [pid 51003:tid 51069] [remote 64.131.86.2:52808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.86.131.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "audiomart.in"] [uri "/wp-login.php"] [unique_id "ajCxjcpsKyvb75pkSvZzugAB2UE"]
[Mon Jun 15 20:14:37.363479 2026] [security2:error] [pid 51003:tid 51143] [client 57.141.14.62:36360] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCxjcpsKyvb75pkSvZzdgABmSY"]
[Mon Jun 15 20:14:37.376565 2026] [security2:error] [pid 51003:tid 51204] [client 57.141.14.11:41621] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCxjcpsKyvb75pkSvZzYwAB1hY"]
[Mon Jun 15 20:14:37.402790 2026] [security2:error] [pid 51003:tid 51053] [remote 2a03:2880:f806:2:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ruchini.hemani.finance"] [uri "/index.php"] [unique_id "ajCxjcpsKyvb75pkSvZzjAABuDE"]
[Mon Jun 15 20:14:37.420582 2026] [security2:error] [pid 51003:tid 51188] [client 162.214.80.21:18228] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "talkmint.com"] [uri "/wp-content/uploads/2023/11/logo.png.webp"] [unique_id "ajCxjcpsKyvb75pkSvZzwgAAAcY"]
[Mon Jun 15 20:14:37.439735 2026] [security2:error] [pid 51003:tid 51244] [client 87.250.224.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxjcpsKyvb75pkSvZzvwAAAf4"]
[Mon Jun 15 20:14:37.441646 2026] [security2:error] [pid 51003:tid 51072] [remote 104.155.29.73:56493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.29.155.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hydlab.co.in"] [uri "/wp-login.php"] [unique_id "ajCxjcpsKyvb75pkSvZzxQAB2EQ"], referer: https://hydlab.co.in/wp-login.php
[Mon Jun 15 20:14:37.441828 2026] [security2:error] [pid 51003:tid 51066] [remote 87.250.224.229:60610] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxjcpsKyvb75pkSvZztAABpj4"]
[Mon Jun 15 20:14:37.445913 2026] [security2:error] [pid 51003:tid 51235] [client 162.214.80.21:18236] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "talkmint.com"] [uri "/wp-content/uploads/2023/11/footer-logo.png.webp"] [unique_id "ajCxjcpsKyvb75pkSvZzxwAAAfU"]
[Mon Jun 15 20:14:37.455303 2026] [security2:error] [pid 51003:tid 51209] [client 213.180.203.161:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxjcpsKyvb75pkSvZzwQAAAds"]
[Mon Jun 15 20:14:37.458165 2026] [security2:error] [pid 51003:tid 51145] [client 213.180.203.161:47314] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxjcpsKyvb75pkSvZztgABmz0"]
[Mon Jun 15 20:14:37.466519 2026] [security2:error] [pid 51003:tid 51181] [client 120.29.91.106:1791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.91.29.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rahulshanu.com"] [uri "/xmlrpc.php"] [unique_id "ajCxjcpsKyvb75pkSvZzyQAAAb8"]
[Mon Jun 15 20:14:37.466715 2026] [security2:error] [pid 51003:tid 51181] [client 120.29.91.106:1791] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rahulshanu.com"] [uri "/xmlrpc.php"] [unique_id "ajCxjcpsKyvb75pkSvZzyQAAAb8"]
[Mon Jun 15 20:14:37.473320 2026] [security2:error] [pid 51003:tid 51076] [remote 194.32.155.65:52784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.155.32.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "enterkitgames.com"] [uri "/wp-login.php"] [unique_id "ajCxjcpsKyvb75pkSvZzzQAB6Eg"], referer: https://enterkitgames.com/wp-login.php
[Mon Jun 15 20:14:37.505358 2026] [security2:error] [pid 51003:tid 51211] [client 136.112.190.143:2328] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talkmint.com"] [uri "/index.php"] [unique_id "ajCxjcpsKyvb75pkSvZzfgAAAd0"]
[Mon Jun 15 20:14:37.523249 2026] [security2:error] [pid 51003:tid 51080] [remote 103.143.207.18:48482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.207.143.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "theomnibliss.com"] [uri "/wp-login.php"] [unique_id "ajCxjcpsKyvb75pkSvZz0wABtEw"]
[Mon Jun 15 20:14:37.534226 2026] [security2:error] [pid 51003:tid 51081] [remote 64.131.86.2:52808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.86.131.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "audiomart.in"] [uri "/wp-login.php"] [unique_id "ajCxjcpsKyvb75pkSvZz1AAB-E0"], referer: https://audiomart.in/wp-login.php
[Mon Jun 15 20:14:37.661104 2026] [security2:error] [pid 51003:tid 51167] [client 31.219.209.201:54533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.209.219.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCxjcpsKyvb75pkSvZz2QAAAbE"]
[Mon Jun 15 20:14:37.661281 2026] [security2:error] [pid 51003:tid 51167] [client 31.219.209.201:54533] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCxjcpsKyvb75pkSvZz2QAAAbE"]
[Mon Jun 15 20:14:37.682413 2026] [autoindex:error] [pid 51003:tid 51164] [client 167.71.237.18:54252] AH01276: Cannot serve directory /home1/oyzujnmy/public_html/naturashop/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Mon Jun 15 20:14:37.947862 2026] [security2:error] [pid 51003:tid 51089] [remote 103.143.207.18:48482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.207.143.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "theomnibliss.com"] [uri "/wp-login.php"] [unique_id "ajCxjcpsKyvb75pkSvZz5gABlFU"], referer: https://theomnibliss.com/wp-login.php
[Mon Jun 15 20:14:38.165942 2026] [security2:error] [pid 51003:tid 51225] [client 2a03:2880:f806:43:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ruchini.hemani.finance"] [uri "/index.php"] [unique_id "ajCxjspsKyvb75pkSvZz7AAB61s"]
[Mon Jun 15 20:14:38.509542 2026] [security2:error] [pid 51003:tid 51164] [client 87.250.224.252:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxjspsKyvb75pkSvZ0AwAAAa4"]
[Mon Jun 15 20:14:38.513422 2026] [security2:error] [pid 51003:tid 51170] [client 87.250.224.252:56140] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxjspsKyvb75pkSvZz-wABtGM"]
[Mon Jun 15 20:14:38.540646 2026] [security2:error] [pid 51003:tid 51204] [client 192.140.64.94:29916] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCxjspsKyvb75pkSvZ0BQAAAdY"]
[Mon Jun 15 20:14:38.540831 2026] [security2:error] [pid 51003:tid 51204] [client 192.140.64.94:29916] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCxjspsKyvb75pkSvZ0BQAAAdY"]
[Mon Jun 15 20:14:38.824832 2026] [security2:error] [pid 51003:tid 51111] [remote 203.190.11.3:58712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.11.190.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "celticwavessc.ie"] [uri "/wp-login.php"] [unique_id "ajCxjspsKyvb75pkSvZ0DQACAWs"]
[Mon Jun 15 20:14:38.929144 2026] [security2:error] [pid 51003:tid 51194] [client 57.141.14.44:32433] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCxjspsKyvb75pkSvZ0CwABzGo"]
[Mon Jun 15 20:14:38.998428 2026] [security2:error] [pid 51003:tid 51222] [client 5.255.231.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxjspsKyvb75pkSvZ0FgAAAeg"]
[Mon Jun 15 20:14:39.001297 2026] [security2:error] [pid 51003:tid 51149] [client 5.255.231.51:43368] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxjspsKyvb75pkSvZ0EQABn28"]
[Mon Jun 15 20:14:39.022081 2026] [security2:error] [pid 51003:tid 51156] [client 213.180.203.163:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxjspsKyvb75pkSvZ0GAAAAaY"]
[Mon Jun 15 20:14:39.134056 2026] [security2:error] [pid 51003:tid 51174] [client 213.180.203.163:47092] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxjspsKyvb75pkSvZ0FAABuHA"]
[Mon Jun 15 20:14:39.261981 2026] [security2:error] [pid 51003:tid 51169] [client 38.19.35.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kthemani.com"] [uri "/index.php"] [unique_id "ajCxjcpsKyvb75pkSvZzgAABsy0"]
[Mon Jun 15 20:14:39.359285 2026] [security2:error] [pid 51003:tid 51127] [remote 47.128.62.51:39920] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "astonetech.com"] [uri "/men/tops-men/hoodies-and-sweatshirts-men.html"] [unique_id "ajCxj8psKyvb75pkSvZ0LAABnXs"]
[Mon Jun 15 20:14:39.595763 2026] [security2:error] [pid 51003:tid 51048] [remote 57.141.14.73:33030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.14.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wilsonoverseas.com"] [uri "/items/E571958389"] [unique_id "ajCxj8psKyvb75pkSvZ0OAAB6Sw"]
[Mon Jun 15 20:14:39.944420 2026] [security2:error] [pid 51003:tid 51067] [remote 203.190.11.3:58712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.11.190.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "celticwavessc.ie"] [uri "/wp-login.php"] [unique_id "ajCxj8psKyvb75pkSvZ0TgABnj8"], referer: https://celticwavessc.ie/wp-login.php
[Mon Jun 15 20:14:40.061101 2026] [security2:error] [pid 51003:tid 51172] [client 95.108.213.189:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxkMpsKyvb75pkSvZ0bgAAAbY"]
[Mon Jun 15 20:14:40.064009 2026] [security2:error] [pid 51003:tid 51245] [client 95.108.213.189:46700] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxj8psKyvb75pkSvZ0bAAB_0A"]
[Mon Jun 15 20:14:40.390080 2026] [security2:error] [pid 51003:tid 51154] [client 159.65.245.128:62706] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "theomnibliss.com"] [uri "/wp-login.php"] [unique_id "ajCxkMpsKyvb75pkSvZ0egAAAaQ"]
[Mon Jun 15 20:14:40.707125 2026] [security2:error] [pid 51003:tid 51243] [client 159.65.245.128:62776] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "theomnibliss.com"] [uri "/wp-login.php"] [unique_id "ajCxkMpsKyvb75pkSvZ0iQAAAf0"]
[Mon Jun 15 20:14:40.710285 2026] [security2:error] [pid 51003:tid 51149] [client 47.128.119.133:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCxkMpsKyvb75pkSvZ0eQABnyI"]
[Mon Jun 15 20:14:40.825589 2026] [security2:error] [pid 51003:tid 51012] [remote 57.141.14.73:40312] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCxkMpsKyvb75pkSvZ0igACDgg"]
[Mon Jun 15 20:14:40.979724 2026] [security2:error] [pid 51003:tid 51150] [client 57.141.14.102:49357] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCxkMpsKyvb75pkSvZ0jwABoEM"]
[Mon Jun 15 20:14:40.980066 2026] [security2:error] [pid 51003:tid 51214] [client 95.108.213.191:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxkMpsKyvb75pkSvZ0lgAAAeA"]
[Mon Jun 15 20:14:40.982661 2026] [security2:error] [pid 51003:tid 51181] [client 95.108.213.191:43778] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxkMpsKyvb75pkSvZ0kwABv0Q"]
[Mon Jun 15 20:14:40.983915 2026] [security2:error] [pid 51003:tid 51248] [client 47.79.206.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "societytodaynews.com"] [uri "/index.php"] [unique_id "ajCxkMpsKyvb75pkSvZ0jQAAAgI"], referer: https://www.google.com/
[Mon Jun 15 20:14:41.002552 2026] [security2:error] [pid 51003:tid 51065] [remote 57.141.14.73:40318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.14.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wilsonoverseas.com"] [uri "/items/E571958389"] [unique_id "ajCxkcpsKyvb75pkSvZ0mQAB7j0"]
[Mon Jun 15 20:14:41.467310 2026] [security2:error] [pid 51003:tid 51207] [client 57.141.14.20:57706] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "majividyarthikes.com"] [uri "/index.php"] [unique_id "ajCxkcpsKyvb75pkSvZ0pwAB2Uo"]
[Mon Jun 15 20:14:41.468341 2026] [security2:error] [pid 51003:tid 51222] [client 213.180.203.250:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxkcpsKyvb75pkSvZ0uAAAAeg"]
[Mon Jun 15 20:14:41.479790 2026] [security2:error] [pid 51003:tid 51166] [client 213.180.203.250:45172] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxkcpsKyvb75pkSvZ0tgABsFE"]
[Mon Jun 15 20:14:41.626526 2026] [security2:error] [pid 51003:tid 51206] [client 109.70.100.14:51718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.100.70.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arasansoap.com"] [uri "/xmlrpc.php"] [unique_id "ajCxkcpsKyvb75pkSvZ0wQAAAdg"], referer: https://arasansoap.com/
[Mon Jun 15 20:14:41.626779 2026] [security2:error] [pid 51003:tid 51206] [client 109.70.100.14:51718] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arasansoap.com"] [uri "/xmlrpc.php"] [unique_id "ajCxkcpsKyvb75pkSvZ0wQAAAdg"], referer: https://arasansoap.com/
[Mon Jun 15 20:14:41.713195 2026] [security2:error] [pid 51003:tid 51091] [remote 57.141.14.73:40322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.14.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wilsonoverseas.com"] [uri "/items/E571958389"] [unique_id "ajCxkcpsKyvb75pkSvZ0yQABsVc"]
[Mon Jun 15 20:14:42.035620 2026] [security2:error] [pid 51003:tid 51243] [client 57.141.14.89:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "assetplusproperty.com"] [uri "/index.php"] [unique_id "ajCxkcpsKyvb75pkSvZ0tQAAAf0"]
[Mon Jun 15 20:14:42.059082 2026] [security2:error] [pid 51003:tid 51172] [client 87.250.224.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxkspsKyvb75pkSvZ00QAAAbY"]
[Mon Jun 15 20:14:42.061606 2026] [security2:error] [pid 51003:tid 51258] [client 87.250.224.34:46918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxkcpsKyvb75pkSvZ0zwACDBk"]
[Mon Jun 15 20:14:42.075556 2026] [security2:error] [pid 51003:tid 51094] [remote 162.254.36.150:35224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.36.254.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mdxhassan.com"] [uri "/wp-login.php"] [unique_id "ajCxkspsKyvb75pkSvZ00wABvVo"]
[Mon Jun 15 20:14:42.078951 2026] [security2:error] [pid 51003:tid 51141] [client 47.128.119.133:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCxkcpsKyvb75pkSvZ0vQABlw4"], referer: https://mywordsnthoughts.com/myworld/tag/priyanka-arul-mohan/
[Mon Jun 15 20:14:42.190317 2026] [security2:error] [pid 51003:tid 51212] [client 47.128.119.133:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCxkcpsKyvb75pkSvZ0wAAB3iQ"], referer: https://mywordsnthoughts.com/myworld/tag/priyanka-arul-mohan/
[Mon Jun 15 20:14:42.337403 2026] [security2:error] [pid 51003:tid 51050] [remote 162.254.36.150:35224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.36.254.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mdxhassan.com"] [uri "/wp-login.php"] [unique_id "ajCxkspsKyvb75pkSvZ03AABxS4"], referer: https://mdxhassan.com/wp-login.php
[Mon Jun 15 20:14:42.375553 2026] [security2:error] [pid 51003:tid 51051] [remote 91.146.99.41:34494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.99.146.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "astonetech.com"] [uri "/wp-login.php"] [unique_id "ajCxkspsKyvb75pkSvZ03gABwi8"]
[Mon Jun 15 20:14:42.550387 2026] [security2:error] [pid 51003:tid 51214] [client 95.108.213.223:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxkspsKyvb75pkSvZ06AAAAeA"]
[Mon Jun 15 20:14:42.552251 2026] [security2:error] [pid 51003:tid 51149] [client 95.108.213.223:49516] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxkspsKyvb75pkSvZ05QABn2Y"]
[Mon Jun 15 20:14:42.579429 2026] [security2:error] [pid 51003:tid 51207] [client 89.124.113.107:30174] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "89.124.113.107" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.c-barrel-menu.com"] [uri "/wp-comments-post.php"] [unique_id "ajCxkspsKyvb75pkSvZ06wAAAdk"], referer: https://www.c-barrel-menu.com/old-timers-breakfast/
[Mon Jun 15 20:14:42.579569 2026] [security2:error] [pid 51003:tid 51207] [client 89.124.113.107:30174] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.c-barrel-menu.com"] [uri "/wp-comments-post.php"] [unique_id "ajCxkspsKyvb75pkSvZ06wAAAdk"], referer: https://www.c-barrel-menu.com/old-timers-breakfast/
[Mon Jun 15 20:14:42.712277 2026] [security2:error] [pid 51003:tid 51111] [remote 91.146.99.41:34494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.99.146.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "astonetech.com"] [uri "/wp-login.php"] [unique_id "ajCxkspsKyvb75pkSvZ08AACDGs"], referer: https://astonetech.com/wp-login.php
[Mon Jun 15 20:14:42.771574 2026] [security2:error] [pid 51003:tid 51055] [remote 57.141.14.14:51428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCxkspsKyvb75pkSvZ07gABkzM"]
[Mon Jun 15 20:14:42.807543 2026] [security2:error] [pid 51003:tid 51114] [remote 173.236.215.92:58000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.215.236.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intactinsurance.co.in"] [uri "/wp-login.php"] [unique_id "ajCxkspsKyvb75pkSvZ09gABt24"]
[Mon Jun 15 20:14:42.830049 2026] [security2:error] [pid 51003:tid 51155] [client 47.79.206.169:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "db.geeksinsight.com"] [uri "/index.php"] [unique_id "ajCxkspsKyvb75pkSvZ09QAAAaU"], referer: https://www.google.com/
[Mon Jun 15 20:14:42.857929 2026] [security2:error] [pid 51003:tid 51209] [client 192.185.4.166:17070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "hydlab.co.in"] [uri "/wp-login.php"] [unique_id "ajCxkspsKyvb75pkSvZ0-AAB218"]
[Mon Jun 15 20:14:42.891703 2026] [security2:error] [pid 51003:tid 51231] [client 104.164.171.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCxkspsKyvb75pkSvZ04AAB8V4"], referer: https://mywordsnthoughts.com/50-must-see-bollywood-films-with-lead-actor-or-actress-in-a-double-role/
[Mon Jun 15 20:14:42.990779 2026] [security2:error] [pid 51003:tid 51115] [remote 119.195.102.159:36968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.102.195.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "subswaymenu.com"] [uri "/wp-login.php"] [unique_id "ajCxkspsKyvb75pkSvZ0_QABzW8"]
[Mon Jun 15 20:14:43.008144 2026] [security2:error] [pid 51003:tid 51251] [client 104.164.171.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCxkspsKyvb75pkSvZ05gACBWI"], referer: https://mywordsnthoughts.com/50-must-see-bollywood-films-with-lead-actor-or-actress-in-a-double-role/
[Mon Jun 15 20:14:43.033483 2026] [security2:error] [pid 51003:tid 51183] [client 213.180.203.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxkspsKyvb75pkSvZ0_gAAAcE"]
[Mon Jun 15 20:14:43.041599 2026] [security2:error] [pid 51003:tid 51141] [client 213.180.203.63:45096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxkspsKyvb75pkSvZ0-wABl3E"]
[Mon Jun 15 20:14:43.042176 2026] [security2:error] [pid 51003:tid 51116] [remote 111.225.148.8:46870] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.steelsalesco.com"] [uri "/stainless-steel-instrumentation-tube-fittings-supplier-manufacturer/"] [unique_id "ajCxk8psKyvb75pkSvZ0_wAB83A"]
[Mon Jun 15 20:14:43.068131 2026] [security2:error] [pid 51003:tid 51133] [client 47.128.127.85:10268] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.tcspune.in"] [uri "/robots.txt"] [unique_id "ajCxk8psKyvb75pkSvZ1AAAAAY8"]
[Mon Jun 15 20:14:43.145869 2026] [security2:error] [pid 51003:tid 51180] [client 37.67.39.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kthemani.com"] [uri "/index.php"] [unique_id "ajCxkMpsKyvb75pkSvZ0mAABvkY"]
[Mon Jun 15 20:14:43.308077 2026] [security2:error] [pid 51003:tid 51218] [client 82.7.190.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kthemani.com"] [uri "/index.php"] [unique_id "ajCxkcpsKyvb75pkSvZ0owAAAeQ"]
[Mon Jun 15 20:14:43.459170 2026] [security2:error] [pid 51003:tid 51035] [remote 119.195.102.159:36968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.102.195.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "subswaymenu.com"] [uri "/wp-login.php"] [unique_id "ajCxk8psKyvb75pkSvZ1GAABkR8"], referer: https://subswaymenu.com/wp-login.php
[Mon Jun 15 20:14:43.643114 2026] [security2:error] [pid 51003:tid 51194] [client 95.108.213.192:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxk8psKyvb75pkSvZ1IQAAAcw"]
[Mon Jun 15 20:14:43.649473 2026] [security2:error] [pid 51003:tid 51151] [client 95.108.213.192:42392] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxk8psKyvb75pkSvZ1HQABoSc"]
[Mon Jun 15 20:14:43.777219 2026] [security2:error] [pid 51003:tid 51056] [remote 111.225.149.144:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "niftystags.com"] [uri "/"] [unique_id "ajCxk8psKyvb75pkSvZ1JQAB2zQ"]
[Mon Jun 15 20:14:43.778727 2026] [security2:error] [pid 51003:tid 51215] [client 31.219.209.201:55152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.209.219.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCxk8psKyvb75pkSvZ1JgAAAeE"]
[Mon Jun 15 20:14:43.778841 2026] [security2:error] [pid 51003:tid 51215] [client 31.219.209.201:55152] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCxk8psKyvb75pkSvZ1JgAAAeE"]
[Mon Jun 15 20:14:43.939585 2026] [security2:error] [pid 51003:tid 51252] [client 57.141.14.96:26519] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCxk8psKyvb75pkSvZ1KQACBnc"]
[Mon Jun 15 20:14:44.599149 2026] [security2:error] [pid 51003:tid 51216] [client 104.207.59.194:38121] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:< ?script|(?:<|< ?/)(?:(?:java|vb)script|about|applet|activex|chrome|qx?ss|embed)|< ?/?i?frame\\\\b)" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1079"] [id "340147"] [rev "141"] [msg "Atomicorp.com WAF Rules: Potential Cross Site Scripting Attack"] [data "<script"] [severity "CRITICAL"] [hostname "procrastinatingworker.com"] [uri "/"] [unique_id "ajCxlMpsKyvb75pkSvZ1QAAAAeI"]
[Mon Jun 15 20:14:44.759942 2026] [security2:error] [pid 51003:tid 51210] [client 104.207.59.194:38121] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\< ?(?:img ?/? src ?=|body\\\\b|input\\\\b).{1,100}\\\\bon(?:error|load|focus)\\\\b ?=" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "989"] [id "340099"] [rev "4"] [msg "Atomicorp.com WAF Rules: cross site scripting attempt"] [severity "CRITICAL"] [hostname "procrastinatingworker.com"] [uri "/"] [unique_id "ajCxlMpsKyvb75pkSvZ1RAAAAdw"]
[Mon Jun 15 20:14:44.949373 2026] [security2:error] [pid 51003:tid 51207] [client 120.29.91.106:1938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.91.29.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rahulshanu.com"] [uri "/xmlrpc.php"] [unique_id "ajCxlMpsKyvb75pkSvZ1SgAAAdk"]
[Mon Jun 15 20:14:44.949464 2026] [security2:error] [pid 51003:tid 51207] [client 120.29.91.106:1938] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rahulshanu.com"] [uri "/xmlrpc.php"] [unique_id "ajCxlMpsKyvb75pkSvZ1SgAAAdk"]
[Mon Jun 15 20:14:45.042798 2026] [security2:error] [pid 51003:tid 51252] [client 5.255.231.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxlcpsKyvb75pkSvZ1UgAAAgY"]
[Mon Jun 15 20:14:45.044487 2026] [security2:error] [pid 51003:tid 51177] [client 5.255.231.62:35006] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxlMpsKyvb75pkSvZ1UAABu0I"]
[Mon Jun 15 20:14:45.216007 2026] [security2:error] [pid 51003:tid 51232] [client 213.180.203.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxlcpsKyvb75pkSvZ1WQAAAfI"]
[Mon Jun 15 20:14:45.219481 2026] [security2:error] [pid 51003:tid 51172] [client 213.180.203.9:45904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxlcpsKyvb75pkSvZ1VwABtng"]
[Mon Jun 15 20:14:45.984511 2026] [security2:error] [pid 51003:tid 51072] [remote 57.141.14.108:38905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.14.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wilsonoverseas.com"] [uri "/items/E571958389"] [unique_id "ajCxlcpsKyvb75pkSvZ1cQABt0Q"]
[Mon Jun 15 20:14:46.023638 2026] [security2:error] [pid 51003:tid 51076] [remote 216.244.66.229:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.smgl.org"] [uri "/products_images/Silver-Cluster-Necklace/big/Necklace65.jpg"] [unique_id "ajCxlspsKyvb75pkSvZ1eQAB20g"]
[Mon Jun 15 20:14:46.023825 2026] [security2:error] [pid 51003:tid 51209] [client 216.244.66.229:0] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.smgl.org"] [uri "/products_images/Silver-Cluster-Necklace/big/Necklace65.jpg"] [unique_id "ajCxlspsKyvb75pkSvZ1eQAB20g"]
[Mon Jun 15 20:14:46.075315 2026] [security2:error] [pid 51003:tid 51221] [client 104.207.36.168:61245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.36.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rajunandkardeputycollector.blog"] [uri "/wp-login.php"] [unique_id "ajCxlspsKyvb75pkSvZ1fAAAAec"], referer: https://rajunandkardeputycollector.blog/wp-login.php
[Mon Jun 15 20:14:46.084767 2026] [security2:error] [pid 51003:tid 51034] [remote 57.141.14.72:42427] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCxlcpsKyvb75pkSvZ1dAABrB4"]
[Mon Jun 15 20:14:46.095308 2026] [security2:error] [pid 51003:tid 51152] [client 213.180.203.161:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxlspsKyvb75pkSvZ1ewAAAaI"]
[Mon Jun 15 20:14:46.105115 2026] [security2:error] [pid 51003:tid 51171] [client 213.180.203.161:49284] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxlspsKyvb75pkSvZ1dwABtUs"]
[Mon Jun 15 20:14:46.602100 2026] [security2:error] [pid 51003:tid 51191] [client 45.170.19.51:25657] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.mahavirgems.in"] [uri "/index.php"] [unique_id "ajCxlspsKyvb75pkSvZ1hQAAAck"]
[Mon Jun 15 20:14:46.614829 2026] [security2:error] [pid 51003:tid 51078] [remote 74.7.227.178:56602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "softhubtechno.ehx.czu.mybluehostin.me"] [uri "/images/js/js/Admin/logo/images/clients/img/carrer.php"] [unique_id "ajCxlspsKyvb75pkSvZ1iwABr0o"], referer: https://softhubtechno.ehx.czu.mybluehostin.me/images/js/js/Admin/logo/images/clients/img/logo.png
[Mon Jun 15 20:14:46.693424 2026] [security2:error] [pid 51003:tid 51145] [client 104.207.49.26:55845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.49.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rajunandkardeputycollector.blog"] [uri "/wp-login.php"] [unique_id "ajCxlspsKyvb75pkSvZ1jAAAAZs"], referer: https://rajunandkardeputycollector.blog/wp-login.php
[Mon Jun 15 20:14:47.147939 2026] [security2:error] [pid 51003:tid 51194] [client 87.250.224.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxl8psKyvb75pkSvZ1mgAAAcw"]
[Mon Jun 15 20:14:47.155495 2026] [security2:error] [pid 51003:tid 51203] [client 87.250.224.229:42736] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxl8psKyvb75pkSvZ1mAAB1T4"]
[Mon Jun 15 20:14:47.251865 2026] [security2:error] [pid 51003:tid 51157] [client 45.3.42.102:9429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.42.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rajunandkardeputycollector.blog"] [uri "/wp-login.php"] [unique_id "ajCxl8psKyvb75pkSvZ1mwAAAac"], referer: https://rajunandkardeputycollector.blog/wp-login.php
[Mon Jun 15 20:14:47.540397 2026] [security2:error] [pid 51003:tid 51094] [remote 57.141.14.8:56295] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCxl8psKyvb75pkSvZ1rQABwVo"]
[Mon Jun 15 20:14:47.651395 2026] [security2:error] [pid 51003:tid 51168] [client 87.250.224.252:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxl8psKyvb75pkSvZ11wAAAbI"]
[Mon Jun 15 20:14:47.656263 2026] [security2:error] [pid 51003:tid 51252] [client 87.250.224.252:48588] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxl8psKyvb75pkSvZ1vwACBmA"]
[Mon Jun 15 20:14:47.791429 2026] [security2:error] [pid 51003:tid 51147] [client 65.111.15.93:64137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.15.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rajunandkardeputycollector.blog"] [uri "/wp-login.php"] [unique_id "ajCxl8psKyvb75pkSvZ13wAAAZ0"], referer: https://rajunandkardeputycollector.blog/wp-login.php
[Mon Jun 15 20:14:48.401977 2026] [security2:error] [pid 51003:tid 51115] [remote 103.127.30.137:36446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.30.127.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "unitopaquacare.com"] [uri "/wp-login.php"] [unique_id "ajCxmMpsKyvb75pkSvZ1-gACCG8"]
[Mon Jun 15 20:14:48.564760 2026] [security2:error] [pid 51003:tid 51224] [client 100.28.118.16:19247] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "conneqt.webiknows.net"] [uri "/robots.txt"] [unique_id "ajCxmMpsKyvb75pkSvZ2AgAAAeo"]
[Mon Jun 15 20:14:48.638209 2026] [security2:error] [pid 51003:tid 51138] [client 192.185.4.147:42538] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "banacombaitea.com"] [uri "/wp-login.php"] [unique_id "ajCxmMpsKyvb75pkSvZ18AABlF8"], referer: https://banacombaitea.com/wp-login.php
[Mon Jun 15 20:14:48.828119 2026] [security2:error] [pid 51003:tid 51105] [remote 103.127.30.137:36446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.30.127.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "unitopaquacare.com"] [uri "/wp-login.php"] [unique_id "ajCxmMpsKyvb75pkSvZ2CgACCmU"], referer: https://unitopaquacare.com/wp-login.php
[Mon Jun 15 20:14:49.077440 2026] [security2:error] [pid 51003:tid 51154] [client 192.140.64.94:29536] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCxmMpsKyvb75pkSvZ2DgAAAaQ"]
[Mon Jun 15 20:14:49.077633 2026] [security2:error] [pid 51003:tid 51154] [client 192.140.64.94:29536] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCxmMpsKyvb75pkSvZ2DgAAAaQ"]
[Mon Jun 15 20:14:49.195803 2026] [security2:error] [pid 51003:tid 51188] [client 57.141.14.73:40340] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCxmcpsKyvb75pkSvZ2EAABxnk"]
[Mon Jun 15 20:14:49.341827 2026] [security2:error] [pid 51003:tid 51255] [client 47.79.200.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mycoimbatore.com"] [uri "/index.php"] [unique_id "ajCxmMpsKyvb75pkSvZ2CAAAAgk"], referer: https://www.google.com/
[Mon Jun 15 20:14:49.405292 2026] [rewrite:error] [pid 51003:tid 51147] [client 47.79.199.34:16874] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:14:49.528055 2026] [security2:error] [pid 51003:tid 51182] [client 2a03:2880:f806:41:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ruchini.hemani.finance"] [uri "/index.php"] [unique_id "ajCxmcpsKyvb75pkSvZ2GgABwH0"]
[Mon Jun 15 20:14:49.591937 2026] [security2:error] [pid 51003:tid 51246] [client 57.141.14.45:27014] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "majividyarthikes.com"] [uri "/index.php"] [unique_id "ajCxmcpsKyvb75pkSvZ2EwACAHw"]
[Mon Jun 15 20:14:49.814441 2026] [security2:error] [pid 51003:tid 51045] [remote 74.7.243.230:47596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shreeramsweets-co-in.xgh.ggk.mybluehostin.me"] [uri "/plugins/owl-carousel/js/css/plugins/owl-carousel/images/js/images_scroller/plugins/owl-carousel/images/js/bakers.php"] [unique_id "ajCxmcpsKyvb75pkSvZ2OQABqyk"], referer: https://shreeramsweets-co-in.xgh.ggk.mybluehostin.me/plugins/owl-carousel/js/css/plugins/owl-carousel/images/js/images_scroller/plugins/owl-carousel/images/js/jquery.min.js
[Mon Jun 15 20:14:49.860809 2026] [rewrite:error] [pid 51003:tid 51210] [client 47.79.199.34:16874] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:14:50.032786 2026] [security2:error] [pid 51003:tid 51167] [client 54.90.8.255:57857] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "conneqt.webiknows.net"] [uri "/bsmquqm/local-dimming-subtitles.html"] [unique_id "ajCxmspsKyvb75pkSvZ2XwAAAbE"]
[Mon Jun 15 20:14:50.149864 2026] [security2:error] [pid 51003:tid 51213] [client 52.167.144.174:52094] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.unitopaquacare.com"] [uri "/index.php"] [unique_id "ajCxmspsKyvb75pkSvZ2YwAB3ww"]
[Mon Jun 15 20:14:50.153749 2026] [security2:error] [pid 51003:tid 51197] [client 90.160.92.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kthemani.com"] [uri "/index.php"] [unique_id "ajCxmMpsKyvb75pkSvZ19gAAAc8"]
[Mon Jun 15 20:14:50.399959 2026] [security2:error] [pid 51003:tid 51072] [remote 216.244.66.229:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.smgl.org"] [uri "/products_images/Silver-Cluster-Necklace/big/Necklace90.jpg"] [unique_id "ajCxmspsKyvb75pkSvZ2cAAB3EQ"]
[Mon Jun 15 20:14:50.400115 2026] [security2:error] [pid 51003:tid 51210] [client 216.244.66.229:0] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.smgl.org"] [uri "/products_images/Silver-Cluster-Necklace/big/Necklace90.jpg"] [unique_id "ajCxmspsKyvb75pkSvZ2cAAB3EQ"]
[Mon Jun 15 20:14:50.614027 2026] [security2:error] [pid 51003:tid 51207] [client 57.141.14.59:48849] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCxmspsKyvb75pkSvZ2cwAB2RU"]
[Mon Jun 15 20:14:50.690441 2026] [rewrite:error] [pid 51003:tid 51020] [remote 47.79.197.77:7140] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:14:50.719198 2026] [security2:error] [pid 51003:tid 51252] [client 82.224.68.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kthemani.com"] [uri "/index.php"] [unique_id "ajCxmMpsKyvb75pkSvZ2CQACBkY"]
[Mon Jun 15 20:14:50.947024 2026] [rewrite:error] [pid 51003:tid 51058] [remote 47.79.197.77:7140] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:14:51.641629 2026] [security2:error] [pid 51003:tid 51222] [client 5.255.231.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxm8psKyvb75pkSvZ2nAAAAeg"]
[Mon Jun 15 20:14:51.644443 2026] [security2:error] [pid 51003:tid 51168] [client 5.255.231.51:58650] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxm8psKyvb75pkSvZ2mQABsgM"]
[Mon Jun 15 20:14:52.163029 2026] [security2:error] [pid 51003:tid 51073] [remote 57.141.14.73:51260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.14.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wilsonoverseas.com"] [uri "/items/E571958389"] [unique_id "ajCxnMpsKyvb75pkSvZ2qwABvUU"]
[Mon Jun 15 20:14:52.188824 2026] [security2:error] [pid 51003:tid 51170] [client 18.235.81.246:57520] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cricket.webiknows.net"] [uri "/r18ws/do-i-need-avx2.html"] [unique_id "ajCxnMpsKyvb75pkSvZ2rwAAAbQ"]
[Mon Jun 15 20:14:52.262524 2026] [security2:error] [pid 51003:tid 51136] [client 213.180.203.163:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxnMpsKyvb75pkSvZ2sgAAAZI"]
[Mon Jun 15 20:14:52.266585 2026] [security2:error] [pid 51003:tid 51249] [client 213.180.203.163:47794] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxnMpsKyvb75pkSvZ2qQACAy4"]
[Mon Jun 15 20:14:52.394045 2026] [security2:error] [pid 51003:tid 51213] [client 57.141.14.112:42936] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCxnMpsKyvb75pkSvZ2swAB3xg"]
[Mon Jun 15 20:14:52.649922 2026] [security2:error] [pid 51003:tid 51020] [remote 46.224.198.211:53466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.198.224.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thevoiceofrk.com"] [uri "/wp-login.php"] [unique_id "ajCxnMpsKyvb75pkSvZ3nAAB9xA"]
[Mon Jun 15 20:14:52.654715 2026] [security2:error] [pid 51003:tid 51074] [remote 103.127.30.137:36460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.30.127.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thedutchunclepizzeria.com"] [uri "/wp-login.php"] [unique_id "ajCxnMpsKyvb75pkSvZ3nwACAEY"]
[Mon Jun 15 20:14:52.687435 2026] [security2:error] [pid 51003:tid 51040] [remote 57.141.14.3:36602] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "wantpg.com"] [uri "/public/index.php/in/sosley-mordovia-russian-federation-2185150.html"] [unique_id "ajCxnMpsKyvb75pkSvZ2pgABoyQ"]
[Mon Jun 15 20:14:52.800275 2026] [security2:error] [pid 51003:tid 51217] [client 95.108.213.189:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxnMpsKyvb75pkSvZ3pAAAAeM"]
[Mon Jun 15 20:14:52.802944 2026] [security2:error] [pid 51003:tid 51183] [client 95.108.213.189:60750] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxnMpsKyvb75pkSvZ3oQABwR0"]
[Mon Jun 15 20:14:52.817400 2026] [rewrite:error] [pid 51003:tid 51080] [remote 47.79.198.228:61436] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:14:53.084146 2026] [rewrite:error] [pid 51003:tid 51032] [remote 47.79.198.228:61436] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:14:53.124913 2026] [security2:error] [pid 51003:tid 51008] [remote 103.127.30.137:36460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.30.127.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thedutchunclepizzeria.com"] [uri "/wp-login.php"] [unique_id "ajCxncpsKyvb75pkSvZ3sgABsgQ"], referer: https://thedutchunclepizzeria.com/wp-login.php
[Mon Jun 15 20:14:53.218153 2026] [security2:error] [pid 51003:tid 51212] [client 95.108.213.191:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxncpsKyvb75pkSvZ3twAAAd4"]
[Mon Jun 15 20:14:53.233832 2026] [security2:error] [pid 51003:tid 51166] [client 95.108.213.191:50366] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxncpsKyvb75pkSvZ3swABsD0"]
[Mon Jun 15 20:14:53.292296 2026] [security2:error] [pid 51003:tid 51230] [client 131.221.174.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "steelsalesco.com"] [uri "/index.php"] [unique_id "ajCxncpsKyvb75pkSvZ3uAAAAfA"]
[Mon Jun 15 20:14:53.708650 2026] [security2:error] [pid 51003:tid 51202] [client 213.180.203.250:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxncpsKyvb75pkSvZ3xgAAAdQ"]
[Mon Jun 15 20:14:53.722022 2026] [security2:error] [pid 51003:tid 51192] [client 213.180.203.250:35378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxncpsKyvb75pkSvZ3xAAByg4"]
[Mon Jun 15 20:14:53.787584 2026] [security2:error] [pid 51003:tid 51066] [remote 57.141.14.60:56018] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCxncpsKyvb75pkSvZ3xwAB9D4"]
[Mon Jun 15 20:14:54.025585 2026] [security2:error] [pid 51003:tid 51213] [client 54.163.169.168:2138] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "conneqt.webiknows.net"] [uri "/bsmquqm/calories-in-wine.html"] [unique_id "ajCxnspsKyvb75pkSvZ32wAAAd8"]
[Mon Jun 15 20:14:54.144054 2026] [security2:error] [pid 51003:tid 51044] [remote 46.224.198.211:53466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.198.224.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thevoiceofrk.com"] [uri "/wp-login.php"] [unique_id "ajCxnspsKyvb75pkSvZ34AABzCg"], referer: https://thevoiceofrk.com/wp-login.php
[Mon Jun 15 20:14:54.259389 2026] [security2:error] [pid 51003:tid 51223] [client 87.250.224.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxnspsKyvb75pkSvZ35AAAAek"]
[Mon Jun 15 20:14:54.266935 2026] [security2:error] [pid 51003:tid 51218] [client 87.250.224.34:60940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxnspsKyvb75pkSvZ34gAB5C4"]
[Mon Jun 15 20:14:54.338957 2026] [security2:error] [pid 51003:tid 51233] [client 31.219.209.201:55763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.209.219.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCxnspsKyvb75pkSvZ36AAAAfM"]
[Mon Jun 15 20:14:54.339091 2026] [security2:error] [pid 51003:tid 51233] [client 31.219.209.201:55763] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCxnspsKyvb75pkSvZ36AAAAfM"]
[Mon Jun 15 20:14:54.609313 2026] [security2:error] [pid 51003:tid 51113] [remote 216.244.66.229:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.smgl.org"] [uri "/products_images/Silver-Cluster-Necklace/big/Necklace168.jpg"] [unique_id "ajCxnspsKyvb75pkSvZ39AACA20"]
[Mon Jun 15 20:14:54.609495 2026] [security2:error] [pid 51003:tid 51249] [client 216.244.66.229:0] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.smgl.org"] [uri "/products_images/Silver-Cluster-Necklace/big/Necklace168.jpg"] [unique_id "ajCxnspsKyvb75pkSvZ39AACA20"]
[Mon Jun 15 20:14:54.860181 2026] [security2:error] [pid 51003:tid 51176] [client 213.180.203.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxnspsKyvb75pkSvZ3_gAAAbo"]
[Mon Jun 15 20:14:54.865377 2026] [security2:error] [pid 51003:tid 51188] [client 213.180.203.5:59434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxnspsKyvb75pkSvZ3-wABxnE"]
[Mon Jun 15 20:14:54.908397 2026] [rewrite:error] [pid 51003:tid 51107] [remote 47.79.198.230:10796] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:14:55.005958 2026] [security2:error] [pid 51003:tid 51070] [remote 184.107.244.93:39560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.244.107.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aygrealty.com"] [uri "/wp-login.php"] [unique_id "ajCxnspsKyvb75pkSvZ4CwABtkI"]
[Mon Jun 15 20:14:55.035621 2026] [security2:error] [pid 51003:tid 51164] [client 5.255.231.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxnspsKyvb75pkSvZ4DAAAAa4"]
[Mon Jun 15 20:14:55.038843 2026] [security2:error] [pid 51003:tid 51204] [client 5.255.231.51:58650] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxnspsKyvb75pkSvZ4CQAB1m8"]
[Mon Jun 15 20:14:55.164415 2026] [rewrite:error] [pid 51003:tid 51100] [remote 47.79.198.230:10796] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:14:55.189042 2026] [security2:error] [pid 51003:tid 51056] [remote 184.107.244.93:39560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.244.107.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aygrealty.com"] [uri "/wp-login.php"] [unique_id "ajCxn8psKyvb75pkSvZ4EwABxTQ"], referer: https://aygrealty.com/wp-login.php
[Mon Jun 15 20:14:55.190416 2026] [security2:error] [pid 51003:tid 51122] [remote 57.141.14.73:51290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.14.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wilsonoverseas.com"] [uri "/items/E571958389"] [unique_id "ajCxn8psKyvb75pkSvZ4FQAB-XY"]
[Mon Jun 15 20:14:55.241297 2026] [security2:error] [pid 51003:tid 51185] [client 86.28.113.125:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kthemani.com"] [uri "/index.php"] [unique_id "ajCxncpsKyvb75pkSvZ3vgAAAcM"]
[Mon Jun 15 20:14:55.375220 2026] [security2:error] [pid 51003:tid 51177] [client 45.84.107.55:52539] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "gamergreatness.com"] [uri "/index.php"] [unique_id "ajCxn8psKyvb75pkSvZ4EQABuxs"], referer: https://gamergreatness.com/category/gaming-setups
[Mon Jun 15 20:14:55.645548 2026] [security2:error] [pid 51003:tid 51210] [client 57.141.14.88:21444] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCxn8psKyvb75pkSvZ4JwAB3Bc"]
[Mon Jun 15 20:14:55.654211 2026] [security2:error] [pid 51003:tid 51249] [client 120.29.91.106:2029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.91.29.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rahulshanu.com"] [uri "/xmlrpc.php"] [unique_id "ajCxn8psKyvb75pkSvZ4LwAAAgM"]
[Mon Jun 15 20:14:55.654561 2026] [security2:error] [pid 51003:tid 51249] [client 120.29.91.106:2029] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rahulshanu.com"] [uri "/xmlrpc.php"] [unique_id "ajCxn8psKyvb75pkSvZ4LwAAAgM"]
[Mon Jun 15 20:14:55.702520 2026] [security2:error] [pid 51003:tid 51237] [client 57.141.14.73:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aarohiarts.org"] [uri "/index.php"] [unique_id "ajCxn8psKyvb75pkSvZ4JgAAAfc"]
[Mon Jun 15 20:14:55.726189 2026] [security2:error] [pid 51003:tid 51162] [client 213.180.203.103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxn8psKyvb75pkSvZ4NQAAAaw"]
[Mon Jun 15 20:14:55.739465 2026] [security2:error] [pid 51003:tid 51215] [client 213.180.203.103:35422] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxn8psKyvb75pkSvZ4LQAB4So"]
[Mon Jun 15 20:14:56.015029 2026] [security2:error] [pid 51003:tid 51114] [remote 57.141.14.100:27015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.14.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wilsonoverseas.com"] [uri "/items/E571958389"] [unique_id "ajCxn8psKyvb75pkSvZ4dAAB9G4"]
[Mon Jun 15 20:14:56.032500 2026] [rewrite:error] [pid 51003:tid 51222] [client 47.79.199.92:34932] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:14:56.252197 2026] [security2:error] [pid 51003:tid 51200] [client 95.108.213.189:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxoMpsKyvb75pkSvZ4fwAAAdI"]
[Mon Jun 15 20:14:56.253393 2026] [security2:error] [pid 51003:tid 51171] [client 95.108.213.191:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxoMpsKyvb75pkSvZ4kQAAAbU"]
[Mon Jun 15 20:14:56.256792 2026] [security2:error] [pid 51003:tid 51237] [client 95.108.213.189:37680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxoMpsKyvb75pkSvZ4eQAB9w8"]
[Mon Jun 15 20:14:56.257633 2026] [security2:error] [pid 51003:tid 51157] [client 95.108.213.191:50380] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxoMpsKyvb75pkSvZ4eAABp3g"]
[Mon Jun 15 20:14:56.345792 2026] [security2:error] [pid 51003:tid 51182] [client 213.180.203.250:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxoMpsKyvb75pkSvZ4lQAAAcA"]
[Mon Jun 15 20:14:56.347621 2026] [security2:error] [pid 51003:tid 51135] [client 213.180.203.250:35378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxoMpsKyvb75pkSvZ4kwABkUY"]
[Mon Jun 15 20:14:56.397664 2026] [security2:error] [pid 51003:tid 51212] [client 34.224.9.144:62146] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cricket.webiknows.net"] [uri "/r18ws/how-to-get-back-into-working-out-after-2-weeks.html"] [unique_id "ajCxoMpsKyvb75pkSvZ4mAAAAd4"]
[Mon Jun 15 20:14:56.483981 2026] [rewrite:error] [pid 51003:tid 51166] [client 47.79.199.92:34932] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:14:56.650069 2026] [security2:error] [pid 51003:tid 51041] [remote 74.7.227.161:50984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.shreeramsweets.co.in"] [uri "/plugins/lightgallery/js/plugins/lightgallery/js/images_scroller/images/blog/grid/images_scroller/plugins/owl-carousel/css/lightgallery/js/reviews.php"] [unique_id "ajCxoMpsKyvb75pkSvZ4oQAByiU"], referer: https://www.shreeramsweets.co.in/plugins/lightgallery/js/plugins/lightgallery/js/images_scroller/images/blog/grid/images_scroller/plugins/owl-carousel/css/lightgallery/js/lightgallery-all.min.js
[Mon Jun 15 20:14:56.804412 2026] [security2:error] [pid 51003:tid 51199] [client 57.141.14.17:42580] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCxoMpsKyvb75pkSvZ4pAAB0R0"]
[Mon Jun 15 20:14:57.244641 2026] [security2:error] [pid 51003:tid 51079] [remote 184.107.244.93:56300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.244.107.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.12oxenterprises.co"] [uri "/wp-login.php"] [unique_id "ajCxocpsKyvb75pkSvZ4tAABpEs"]
[Mon Jun 15 20:14:57.257269 2026] [security2:error] [pid 51003:tid 51058] [remote 91.146.99.41:60278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.99.146.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dountsmenu.onl"] [uri "/wp-login.php"] [unique_id "ajCxocpsKyvb75pkSvZ4twAB_TY"]
[Mon Jun 15 20:14:57.313935 2026] [rewrite:error] [pid 51003:tid 51018] [remote 47.79.198.33:18632] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:14:57.350282 2026] [security2:error] [pid 51003:tid 51162] [client 87.250.224.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxocpsKyvb75pkSvZ4uwAAAaw"]
[Mon Jun 15 20:14:57.353480 2026] [security2:error] [pid 51003:tid 51249] [client 87.250.224.34:60946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxocpsKyvb75pkSvZ4tQACAwM"]
[Mon Jun 15 20:14:57.423672 2026] [security2:error] [pid 51003:tid 51066] [remote 184.107.244.93:56300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.244.107.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.12oxenterprises.co"] [uri "/wp-login.php"] [unique_id "ajCxocpsKyvb75pkSvZ4vQABoD4"], referer: https://mail.12oxenterprises.co/wp-login.php
[Mon Jun 15 20:14:57.471168 2026] [security2:error] [pid 51003:tid 51208] [client 65.111.3.18:58219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.3.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rajunandkardeputycollector.blog"] [uri "/wp-login.php"] [unique_id "ajCxocpsKyvb75pkSvZ4vgAAAdo"], referer: https://rajunandkardeputycollector.blog/wp-login.php
[Mon Jun 15 20:14:57.496963 2026] [security2:error] [pid 51003:tid 51023] [remote 91.146.99.41:60278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.99.146.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dountsmenu.onl"] [uri "/wp-login.php"] [unique_id "ajCxocpsKyvb75pkSvZ4wQABtRM"], referer: https://dountsmenu.onl/wp-login.php
[Mon Jun 15 20:14:57.571193 2026] [rewrite:error] [pid 51003:tid 51073] [remote 47.79.198.33:18632] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:14:57.663049 2026] [security2:error] [pid 51003:tid 51195] [client 45.84.107.55:52617] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "gamergreatness.com"] [uri "/index.php"] [unique_id "ajCxocpsKyvb75pkSvZ4wAABzQs"], referer: https://gamergreatness.com/category/gaming-tech-updates
[Mon Jun 15 20:14:57.752202 2026] [security2:error] [pid 51003:tid 51113] [remote 216.244.66.229:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.smgl.org"] [uri "/products_images/Silver-Cluster-Necklace/big/Necklace184.jpg"] [unique_id "ajCxocpsKyvb75pkSvZ41AABwG0"]
[Mon Jun 15 20:14:57.752330 2026] [security2:error] [pid 51003:tid 51182] [client 216.244.66.229:0] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.smgl.org"] [uri "/products_images/Silver-Cluster-Necklace/big/Necklace184.jpg"] [unique_id "ajCxocpsKyvb75pkSvZ41AABwG0"]
[Mon Jun 15 20:14:57.752358 2026] [security2:error] [pid 51003:tid 51209] [client 213.180.203.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxocpsKyvb75pkSvZ4zwAAAds"]
[Mon Jun 15 20:14:57.755148 2026] [security2:error] [pid 51003:tid 51168] [client 213.180.203.63:63728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxocpsKyvb75pkSvZ4zAABsls"]
[Mon Jun 15 20:14:57.782257 2026] [security2:error] [pid 51003:tid 51180] [client 95.108.213.223:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxocpsKyvb75pkSvZ40wAAAb4"]
[Mon Jun 15 20:14:57.783776 2026] [security2:error] [pid 51003:tid 51237] [client 95.108.213.223:42608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxocpsKyvb75pkSvZ40AAB91o"]
[Mon Jun 15 20:14:57.853892 2026] [security2:error] [pid 51003:tid 51145] [client 65.111.30.222:18317] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:error. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked - PHP function in Argument - this may be an attack."] [data "exec(,ARGS:error"] [severity "CRITICAL"] [hostname "www.procrastinatingworker.imcorp.in"] [uri "/"] [unique_id "ajCxocpsKyvb75pkSvZ42AAAAZs"]
[Mon Jun 15 20:14:58.257274 2026] [security2:error] [pid 51003:tid 51022] [remote 2a03:2880:f806:c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ruchini.hemani.finance"] [uri "/index.php"] [unique_id "ajCxospsKyvb75pkSvZ48wAB7hI"]
[Mon Jun 15 20:14:58.262573 2026] [security2:error] [pid 51003:tid 51045] [remote 20.153.140.50:58870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ispatalloy.com"] [uri "/wp-login.php"] [unique_id "ajCxospsKyvb75pkSvZ4_QAB9Ck"]
[Mon Jun 15 20:14:58.282313 2026] [security2:error] [pid 51003:tid 51009] [remote 57.141.14.44:39645] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCxospsKyvb75pkSvZ49wACDAU"]
[Mon Jun 15 20:14:58.416083 2026] [security2:error] [pid 51003:tid 51179] [client 47.79.200.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "societytodaynews.com"] [uri "/index.php"] [unique_id "ajCxospsKyvb75pkSvZ4-gAAAb0"], referer: https://www.google.com/
[Mon Jun 15 20:14:58.777585 2026] [security2:error] [pid 51003:tid 51130] [remote 31.3.241.131:34554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.241.3.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "speakingarchaeologically.co.in"] [uri "/wp-login.php"] [unique_id "ajCxospsKyvb75pkSvZ5LgABw34"]
[Mon Jun 15 20:14:58.787160 2026] [security2:error] [pid 51003:tid 51097] [remote 57.141.14.73:51312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.14.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wilsonoverseas.com"] [uri "/items/E571958389"] [unique_id "ajCxospsKyvb75pkSvZ5MgAB210"]
[Mon Jun 15 20:14:58.839751 2026] [security2:error] [pid 51003:tid 51135] [client 44.217.177.142:44421] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "locweld.com"] [uri "/"] [unique_id "ajCxospsKyvb75pkSvZ5NgAAAZE"]
[Mon Jun 15 20:14:58.857814 2026] [security2:error] [pid 51003:tid 51164] [client 213.180.203.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxospsKyvb75pkSvZ5NQAAAa4"]
[Mon Jun 15 20:14:58.867135 2026] [security2:error] [pid 51003:tid 51109] [remote 57.141.14.2:30027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.14.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wilsonoverseas.com"] [uri "/items/E571958389"] [unique_id "ajCxospsKyvb75pkSvZ5NwAB92k"]
[Mon Jun 15 20:14:58.901781 2026] [security2:error] [pid 51003:tid 51224] [client 213.180.203.9:36690] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxospsKyvb75pkSvZ5MwAB6nw"]
[Mon Jun 15 20:14:58.927982 2026] [security2:error] [pid 51003:tid 51136] [client 82.39.0.221:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kthemani.com"] [uri "/index.php"] [unique_id "ajCxocpsKyvb75pkSvZ4sQABkkM"]
[Mon Jun 15 20:14:59.159009 2026] [security2:error] [pid 51003:tid 51174] [client 65.111.26.248:38495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.26.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rajunandkardeputycollector.blog"] [uri "/wp-login.php"] [unique_id "ajCxo8psKyvb75pkSvZ5PwAAAbg"], referer: https://rajunandkardeputycollector.blog/wp-login.php
[Mon Jun 15 20:14:59.413041 2026] [rewrite:error] [pid 51003:tid 51074] [remote 47.79.197.165:1248] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:14:59.460089 2026] [security2:error] [pid 51003:tid 51026] [remote 31.3.241.131:34554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.241.3.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "speakingarchaeologically.co.in"] [uri "/wp-login.php"] [unique_id "ajCxo8psKyvb75pkSvZ5RwABrRY"], referer: https://speakingarchaeologically.co.in/wp-login.php
[Mon Jun 15 20:14:59.484109 2026] [security2:error] [pid 51003:tid 51077] [remote 213.171.208.62:55832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.208.171.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cherubicindia.net"] [uri "/wp-login.php"] [unique_id "ajCxo8psKyvb75pkSvZ5SQABy0k"]
[Mon Jun 15 20:14:59.503575 2026] [security2:error] [pid 51003:tid 51226] [client 192.140.64.94:29978] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCxo8psKyvb75pkSvZ5SgAAAew"]
[Mon Jun 15 20:14:59.506602 2026] [security2:error] [pid 51003:tid 51226] [client 192.140.64.94:29978] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCxo8psKyvb75pkSvZ5SgAAAew"]
[Mon Jun 15 20:14:59.670612 2026] [rewrite:error] [pid 51003:tid 51008] [remote 47.79.197.165:1248] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:14:59.721698 2026] [rewrite:error] [pid 51003:tid 51229] [client 47.79.198.145:53174] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:14:59.744067 2026] [security2:error] [pid 51003:tid 51142] [client 104.207.39.244:20729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.39.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rajunandkardeputycollector.blog"] [uri "/wp-login.php"] [unique_id "ajCxo8psKyvb75pkSvZ5VQAAAZg"], referer: https://rajunandkardeputycollector.blog/wp-login.php
[Mon Jun 15 20:14:59.768792 2026] [security2:error] [pid 51003:tid 51090] [remote 47.128.32.79:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mywordsnthoughts.com"] [uri "/cauliflower-burjia/"] [unique_id "ajCxo8psKyvb75pkSvZ5WAABzFY"]
[Mon Jun 15 20:14:59.889851 2026] [security2:error] [pid 51003:tid 51157] [client 192.185.4.166:41200] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "hydlab.in"] [uri "/wp-login.php"] [unique_id "ajCxo8psKyvb75pkSvZ5WQABp0s"], referer: https://hydlab.in/wp-login.php
[Mon Jun 15 20:14:59.987535 2026] [security2:error] [pid 51003:tid 51159] [client 110.249.201.46:61924] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "archresource.co"] [uri "/robots.txt"] [unique_id "ajCxo8psKyvb75pkSvZ5WwAAAak"]
[Mon Jun 15 20:15:00.095134 2026] [security2:error] [pid 51003:tid 51167] [client 57.141.14.44:39651] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCxo8psKyvb75pkSvZ5XAABsQ4"]
[Mon Jun 15 20:15:00.126081 2026] [security2:error] [pid 51003:tid 51066] [remote 213.171.208.62:55832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.208.171.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cherubicindia.net"] [uri "/wp-login.php"] [unique_id "ajCxpMpsKyvb75pkSvZ5YQABvz4"], referer: https://cherubicindia.net/wp-login.php
[Mon Jun 15 20:15:00.180030 2026] [rewrite:error] [pid 51003:tid 51166] [client 47.79.198.145:53174] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:15:00.284744 2026] [security2:error] [pid 51003:tid 51145] [client 95.108.213.192:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxpMpsKyvb75pkSvZ5awAAAZs"]
[Mon Jun 15 20:15:00.287353 2026] [security2:error] [pid 51003:tid 51205] [client 95.108.213.192:50412] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxpMpsKyvb75pkSvZ5aAAB1xU"]
[Mon Jun 15 20:15:00.501056 2026] [security2:error] [pid 51003:tid 51147] [client 45.61.184.21:24559] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "leafsdiary.com"] [uri "/index.php"] [unique_id "ajCxpMpsKyvb75pkSvZ5ZAAAAZ0"], referer: https://www.google.com/
[Mon Jun 15 20:15:00.616316 2026] [rewrite:error] [pid 51003:tid 51234] [client 47.79.198.43:28364] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:15:00.630674 2026] [security2:error] [pid 51003:tid 51206] [client 192.241.146.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "travelmax.in"] [uri "/index.php"] [unique_id "ajCxpMpsKyvb75pkSvZ5egAB2Fs"], referer: https://travelmax.in/
[Mon Jun 15 20:15:00.987062 2026] [security2:error] [pid 51003:tid 51150] [client 45.84.107.55:57937] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "gamergreatness.com"] [uri "/index.php"] [unique_id "ajCxpMpsKyvb75pkSvZ5hAABoAI"], referer: https://gamergreatness.com/category/how-to
[Mon Jun 15 20:15:00.998288 2026] [rewrite:error] [pid 51003:tid 51129] [remote 47.79.197.198:31356] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:15:01.086284 2026] [rewrite:error] [pid 51003:tid 51245] [client 47.79.198.43:28364] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:15:01.148449 2026] [security2:error] [pid 51003:tid 51222] [client 220.181.108.113:16060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.mahavirgems.in"] [uri "/index.php"] [unique_id "ajCxpMpsKyvb75pkSvZ5hwAB6Gc"]
[Mon Jun 15 20:15:01.159747 2026] [security2:error] [pid 51003:tid 51224] [client 74.7.230.58:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.diggysguide.com"] [uri "/robots.txt"] [unique_id "ajCxpcpsKyvb75pkSvZ5mgAAAeo"]
[Mon Jun 15 20:15:01.172515 2026] [security2:error] [pid 51003:tid 51233] [client 74.7.230.58:41150] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.diggysguide.com"] [uri "/robots.txt"] [unique_id "ajCxpMpsKyvb75pkSvZ5kAAB82I"]
[Mon Jun 15 20:15:01.250788 2026] [rewrite:error] [pid 51003:tid 51100] [remote 47.79.197.198:31356] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:15:01.423138 2026] [security2:error] [pid 51003:tid 51251] [client 57.141.14.73:45520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCxpcpsKyvb75pkSvZ5pQACBRo"]
[Mon Jun 15 20:15:01.429280 2026] [security2:error] [pid 51003:tid 51255] [client 87.250.224.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxpcpsKyvb75pkSvZ5sAAAAgk"]
[Mon Jun 15 20:15:01.437291 2026] [security2:error] [pid 51003:tid 51249] [client 87.250.224.132:60520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxpcpsKyvb75pkSvZ5rQACAyk"]
[Mon Jun 15 20:15:01.528889 2026] [security2:error] [pid 51003:tid 51167] [client 94.159.98.16:53268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.98.159.94.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "socialparindee.com"] [uri "/wp-imag.php"] [unique_id "ajCxpcpsKyvb75pkSvZ5sgAAAbE"], referer: https://socialparindee.com/wp-imag.php
[Mon Jun 15 20:15:01.586732 2026] [rewrite:error] [pid 51003:tid 51050] [remote 47.79.198.212:4894] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:15:01.631624 2026] [security2:error] [pid 51003:tid 51108] [remote 47.128.26.29:49022] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "archresource.co"] [uri "/contests/tomorrows-house/faqs/"] [unique_id "ajCxpcpsKyvb75pkSvZ5vAAB02g"]
[Mon Jun 15 20:15:01.842567 2026] [rewrite:error] [pid 51003:tid 51086] [remote 47.79.198.212:4894] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:15:02.021088 2026] [rewrite:error] [pid 51003:tid 51103] [remote 47.79.198.34:22936] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:15:02.026602 2026] [security2:error] [pid 51003:tid 51046] [remote 102.134.101.35:60512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.101.134.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elitedali.com"] [uri "/wp-login.php"] [unique_id "ajCxpspsKyvb75pkSvZ51wABrSo"]
[Mon Jun 15 20:15:02.289950 2026] [rewrite:error] [pid 51003:tid 51126] [remote 47.79.198.34:22936] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:15:02.570498 2026] [security2:error] [pid 51003:tid 51183] [client 51.89.39.37:27366] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gogurueducationhub.com"] [uri "/index.php"] [unique_id "ajCxpcpsKyvb75pkSvZ5wQABwXc"]
[Mon Jun 15 20:15:02.584726 2026] [security2:error] [pid 51003:tid 51196] [client 91.201.134.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kthemani.com"] [uri "/index.php"] [unique_id "ajCxpMpsKyvb75pkSvZ5fAAAAc4"]
[Mon Jun 15 20:15:02.608995 2026] [security2:error] [pid 51003:tid 51106] [remote 57.141.14.73:45536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.14.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wilsonoverseas.com"] [uri "/items/Z95134704"] [unique_id "ajCxpspsKyvb75pkSvZ58AABx2Y"]
[Mon Jun 15 20:15:02.870966 2026] [security2:error] [pid 51003:tid 51057] [remote 102.134.101.35:60512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.101.134.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elitedali.com"] [uri "/wp-login.php"] [unique_id "ajCxpspsKyvb75pkSvZ5-AAB5zU"], referer: https://elitedali.com/wp-login.php
[Mon Jun 15 20:15:02.960072 2026] [security2:error] [pid 51003:tid 51053] [remote 57.141.14.73:45544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.14.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wilsonoverseas.com"] [uri "/items/E571958389"] [unique_id "ajCxpspsKyvb75pkSvZ5_AABuzE"]
[Mon Jun 15 20:15:03.189299 2026] [security2:error] [pid 51003:tid 51130] [remote 57.141.14.19:30514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCxp8psKyvb75pkSvZ6AQABj34"]
[Mon Jun 15 20:15:03.195445 2026] [security2:error] [pid 51003:tid 51154] [client 47.79.199.126:39824] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.diggysguide.com"] [uri "/index.php"] [unique_id "ajCxp8psKyvb75pkSvZ6AgAAAaQ"]
[Mon Jun 15 20:15:03.726861 2026] [security2:error] [pid 51003:tid 51072] [remote 74.7.243.250:56880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rentswale.ehx.czu.mybluehostin.me"] [uri "/css/admin/uploads/item/admin/uploads/item/css/img/index.php"] [unique_id "ajCxp8psKyvb75pkSvZ6EwAB20Q"], referer: https://rentswale.ehx.czu.mybluehostin.me/css/admin/uploads/item/admin/uploads/item/css/img/log.png
[Mon Jun 15 20:15:03.970990 2026] [security2:error] [pid 51003:tid 51173] [client 47.79.206.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "brainstrom.org"] [uri "/index.php"] [unique_id "ajCxp8psKyvb75pkSvZ6FAABtyc"], referer: https://www.google.com/
[Mon Jun 15 20:15:04.111251 2026] [security2:error] [pid 51003:tid 51083] [remote 14.239.188.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "travelmax.in"] [uri "/index.php"] [unique_id "ajCxqMpsKyvb75pkSvZ6HQABx08"], referer: https://travelmax.in/
[Mon Jun 15 20:15:04.150992 2026] [security2:error] [pid 51003:tid 51218] [client 45.84.107.55:57939] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "gamergreatness.com"] [uri "/index.php"] [unique_id "ajCxp8psKyvb75pkSvZ6HAAB5CQ"], referer: https://gamergreatness.com/category/top-10
[Mon Jun 15 20:15:04.201965 2026] [security2:error] [pid 51003:tid 51258] [client 57.141.14.16:32368] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCxqMpsKyvb75pkSvZ6IQACDAQ"]
[Mon Jun 15 20:15:04.356826 2026] [security2:error] [pid 51003:tid 51058] [remote 57.141.14.2:30041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.14.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wilsonoverseas.com"] [uri "/items/E571958389"] [unique_id "ajCxqMpsKyvb75pkSvZ6KAABoDY"]
[Mon Jun 15 20:15:04.485160 2026] [security2:error] [pid 51003:tid 51011] [remote 103.74.116.219:40522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.116.74.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vksindia.com"] [uri "/wp-login.php"] [unique_id "ajCxqMpsKyvb75pkSvZ6LQABqgc"]
[Mon Jun 15 20:15:04.536700 2026] [security2:error] [pid 51003:tid 51037] [remote 103.127.30.137:59112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.30.127.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.thecoimbatorepharmacy.in"] [uri "/wp-login.php"] [unique_id "ajCxqMpsKyvb75pkSvZ6LwAB_CE"]
[Mon Jun 15 20:15:04.792571 2026] [rewrite:error] [pid 51003:tid 51081] [remote 47.79.197.128:23036] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:15:04.869728 2026] [security2:error] [pid 51003:tid 51221] [client 31.219.209.201:56374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.209.219.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCxqMpsKyvb75pkSvZ6OgAAAec"]
[Mon Jun 15 20:15:04.869824 2026] [security2:error] [pid 51003:tid 51221] [client 31.219.209.201:56374] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCxqMpsKyvb75pkSvZ6OgAAAec"]
[Mon Jun 15 20:15:04.891778 2026] [security2:error] [pid 51003:tid 51104] [remote 103.74.116.219:40522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.116.74.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vksindia.com"] [uri "/wp-login.php"] [unique_id "ajCxqMpsKyvb75pkSvZ6OwAB2GQ"], referer: https://vksindia.com/wp-login.php
[Mon Jun 15 20:15:05.040413 2026] [rewrite:error] [pid 51003:tid 51094] [remote 47.79.197.128:23036] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:15:05.080773 2026] [rewrite:error] [pid 51003:tid 51028] [remote 47.79.197.82:7414] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:15:05.141022 2026] [security2:error] [pid 51003:tid 51187] [client 57.141.14.13:42601] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCxqcpsKyvb75pkSvZ6QwABxQs"]
[Mon Jun 15 20:15:05.246656 2026] [security2:error] [pid 51003:tid 51084] [remote 57.141.14.2:30045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.14.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wilsonoverseas.com"] [uri "/items/E571958389"] [unique_id "ajCxqcpsKyvb75pkSvZ6TAACCVA"]
[Mon Jun 15 20:15:05.331238 2026] [rewrite:error] [pid 51003:tid 51034] [remote 47.79.197.82:7414] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:15:05.687632 2026] [security2:error] [pid 51003:tid 51098] [remote 103.127.30.137:59112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.30.127.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.thecoimbatorepharmacy.in"] [uri "/wp-login.php"] [unique_id "ajCxqcpsKyvb75pkSvZ6VwAB-14"], referer: https://mail.thecoimbatorepharmacy.in/wp-login.php
[Mon Jun 15 20:15:05.934008 2026] [security2:error] [pid 51003:tid 51044] [remote 102.134.101.35:60516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.101.134.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cosmodent360.com"] [uri "/wp-login.php"] [unique_id "ajCxqcpsKyvb75pkSvZ6ZgABmCg"]
[Mon Jun 15 20:15:06.433638 2026] [security2:error] [pid 51003:tid 51022] [remote 102.134.101.35:60516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.101.134.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cosmodent360.com"] [uri "/wp-login.php"] [unique_id "ajCxqspsKyvb75pkSvZ6ewABmhI"], referer: https://cosmodent360.com/wp-login.php
[Mon Jun 15 20:15:06.570747 2026] [security2:error] [pid 51003:tid 51228] [client 43.173.173.156:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCxqspsKyvb75pkSvZ6bgAB7hQ"]
[Mon Jun 15 20:15:06.907547 2026] [rewrite:error] [pid 51003:tid 51076] [remote 47.79.196.221:23764] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:15:07.151428 2026] [security2:error] [pid 51003:tid 51253] [client 57.141.14.110:38756] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCxq8psKyvb75pkSvZ6lwACB2o"]
[Mon Jun 15 20:15:07.175824 2026] [rewrite:error] [pid 51003:tid 51029] [remote 47.79.196.221:23764] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:15:07.259961 2026] [security2:error] [pid 51003:tid 51219] [client 94.233.248.254:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kthemani.com"] [uri "/index.php"] [unique_id "ajCxqcpsKyvb75pkSvZ6UQAB5Rs"]
[Mon Jun 15 20:15:07.316475 2026] [rewrite:error] [pid 51003:tid 51046] [remote 47.79.196.210:59988] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:15:07.577799 2026] [rewrite:error] [pid 51003:tid 51013] [remote 47.79.196.210:59988] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:15:08.244922 2026] [security2:error] [pid 51003:tid 51195] [client 47.79.201.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "brainstrom.org"] [uri "/index.php"] [unique_id "ajCxrMpsKyvb75pkSvZ6yAABzQg"], referer: https://www.google.com/
[Mon Jun 15 20:15:08.438980 2026] [security2:error] [pid 51003:tid 51147] [client 57.141.14.88:29138] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCxrMpsKyvb75pkSvZ6zwABnQ0"]
[Mon Jun 15 20:15:08.708398 2026] [security2:error] [pid 51003:tid 51247] [client 5.255.231.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxrMpsKyvb75pkSvZ64gAAAgE"]
[Mon Jun 15 20:15:08.712036 2026] [security2:error] [pid 51003:tid 51243] [client 5.255.231.62:52630] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxrMpsKyvb75pkSvZ63QAB_Wk"]
[Mon Jun 15 20:15:09.074535 2026] [security2:error] [pid 51003:tid 51052] [remote 216.75.132.223:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.smgl.org"] [uri "/product/wholesale-sterling-silver-rings/mens-rings/418"] [unique_id "ajCxrcpsKyvb75pkSvZ7DgAByzA"], referer: https://www.smgl.org/
[Mon Jun 15 20:15:09.147123 2026] [security2:error] [pid 51003:tid 51097] [remote 43.172.198.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCxrMpsKyvb75pkSvZ64wACBl0"], referer: https://mywordsnthoughts.com/top-5-bollywood-stars-who-made-successful-transition-from-television-to-big-screen/
[Mon Jun 15 20:15:09.234546 2026] [security2:error] [pid 51003:tid 51173] [client 43.172.194.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCxrMpsKyvb75pkSvZ65gABtzc"], referer: https://mywordsnthoughts.com/top-5-bollywood-stars-who-made-successful-transition-from-television-to-big-screen/
[Mon Jun 15 20:15:09.797309 2026] [security2:error] [pid 51003:tid 51068] [remote 74.7.242.32:47042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.242.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "my-eyezzy.webiknows.net"] [uri "/vendor/magnific-popup/vendor/magnific-popup/images/main-banner/images/testimonials/css/images/testimonials/js/main-banner/shap/doctor/index.php"] [unique_id "ajCxrcpsKyvb75pkSvZ7MgAB5UA"], referer: https://my-eyezzy.webiknows.net/vendor/magnific-popup/vendor/magnific-popup/images/main-banner/images/testimonials/css/images/testimonials/js/main-banner/shap/circle-orange-2.png
[Mon Jun 15 20:15:09.828768 2026] [security2:error] [pid 51003:tid 51152] [client 213.180.203.161:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxrcpsKyvb75pkSvZ7MQAAAaI"]
[Mon Jun 15 20:15:09.831459 2026] [security2:error] [pid 51003:tid 51141] [client 213.180.203.161:45530] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxrcpsKyvb75pkSvZ7LQABlzY"]
[Mon Jun 15 20:15:09.990494 2026] [security2:error] [pid 51003:tid 51023] [remote 57.141.14.51:24986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCxrcpsKyvb75pkSvZ7TAABtRM"]
[Mon Jun 15 20:15:10.006509 2026] [security2:error] [pid 51003:tid 51210] [client 192.140.64.94:29923] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCxrspsKyvb75pkSvZ7UAAAAdw"]
[Mon Jun 15 20:15:10.009073 2026] [security2:error] [pid 51003:tid 51210] [client 192.140.64.94:29923] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCxrspsKyvb75pkSvZ7UAAAAdw"]
[Mon Jun 15 20:15:10.311022 2026] [security2:error] [pid 51003:tid 51218] [client 213.180.203.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxrspsKyvb75pkSvZ7WgAAAeQ"]
[Mon Jun 15 20:15:10.311039 2026] [security2:error] [pid 51003:tid 51254] [client 87.250.224.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxrspsKyvb75pkSvZ7WQAAAgg"]
[Mon Jun 15 20:15:10.338915 2026] [security2:error] [pid 51003:tid 51154] [client 213.180.203.5:57286] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxrspsKyvb75pkSvZ7VgABpCs"]
[Mon Jun 15 20:15:10.341892 2026] [security2:error] [pid 51003:tid 51168] [client 87.250.224.229:52268] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxrspsKyvb75pkSvZ7VAABshU"]
[Mon Jun 15 20:15:10.493355 2026] [security2:error] [pid 51003:tid 51190] [client 45.84.107.55:33695] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "gamergreatness.com"] [uri "/index.php"] [unique_id "ajCxrspsKyvb75pkSvZ7WAAByFo"], referer: https://gamergreatness.com/comments/feed
[Mon Jun 15 20:15:10.861070 2026] [security2:error] [pid 51003:tid 51255] [client 162.214.80.21:34740] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "talkmint.com"] [uri "/wp-content/uploads/2023/11/logo.png.webp"] [unique_id "ajCxrspsKyvb75pkSvZ7bQAAAgk"]
[Mon Jun 15 20:15:10.891016 2026] [security2:error] [pid 51003:tid 51251] [client 162.214.80.21:34746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "talkmint.com"] [uri "/wp-content/uploads/2023/11/footer-logo.png.webp"] [unique_id "ajCxrspsKyvb75pkSvZ7bwAAAgU"]
[Mon Jun 15 20:15:10.907960 2026] [security2:error] [pid 51003:tid 51233] [client 5.255.231.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxrspsKyvb75pkSvZ7bgAAAfM"]
[Mon Jun 15 20:15:10.911385 2026] [security2:error] [pid 51003:tid 51039] [remote 104.155.29.73:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.29.155.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "travelmax.in"] [uri "/wp-login.php"] [unique_id "ajCxrspsKyvb75pkSvZ7cAABoiM"]
[Mon Jun 15 20:15:10.945350 2026] [security2:error] [pid 51003:tid 51201] [client 35.243.183.146:17396] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talkmint.com"] [uri "/index.php"] [unique_id "ajCxrspsKyvb75pkSvZ7ZgAAAdM"]
[Mon Jun 15 20:15:10.948145 2026] [security2:error] [pid 51003:tid 51151] [client 5.255.231.51:35796] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxrspsKyvb75pkSvZ7awABoXE"]
[Mon Jun 15 20:15:10.949313 2026] [security2:error] [pid 51003:tid 51034] [remote 43.173.174.239:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.174.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mywordsnthoughts.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ajCxrspsKyvb75pkSvZ7cgABzh4"], referer: https://mywordsnthoughts.com/top-5-bollywood-stars-who-made-successful-transition-from-television-to-big-screen/
[Mon Jun 15 20:15:10.998966 2026] [security2:error] [pid 51003:tid 51244] [client 112.201.136.103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kthemani.com"] [uri "/index.php"] [unique_id "ajCxrcpsKyvb75pkSvZ7FQAAAf4"]
[Mon Jun 15 20:15:11.112187 2026] [security2:error] [pid 51003:tid 51005] [remote 104.155.29.73:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.29.155.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "travelmax.in"] [uri "/wp-login.php"] [unique_id "ajCxr8psKyvb75pkSvZ7fQACCgE"], referer: https://travelmax.in/wp-login.php
[Mon Jun 15 20:15:11.326156 2026] [security2:error] [pid 51003:tid 51182] [client 213.180.203.103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxr8psKyvb75pkSvZ7hwAAAcA"]
[Mon Jun 15 20:15:11.330903 2026] [security2:error] [pid 51003:tid 51250] [client 213.180.203.103:39990] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxr8psKyvb75pkSvZ7hAACBAw"]
[Mon Jun 15 20:15:11.482415 2026] [security2:error] [pid 51003:tid 51190] [client 57.141.14.60:56914] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCxr8psKyvb75pkSvZ7iwAByH0"]
[Mon Jun 15 20:15:11.930826 2026] [security2:error] [pid 51003:tid 51193] [client 95.108.213.189:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxr8psKyvb75pkSvZ7oAAAAcs"]
[Mon Jun 15 20:15:11.937636 2026] [security2:error] [pid 51003:tid 51141] [client 95.108.213.189:63548] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxr8psKyvb75pkSvZ7nAABlwA"]
[Mon Jun 15 20:15:12.208665 2026] [security2:error] [pid 51003:tid 51244] [client 112.86.225.17:40608] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.diggysguide.com"] [uri "/terra/dry-waterhole"] [unique_id "ajCxsMpsKyvb75pkSvZ7rgAAAf4"]
[Mon Jun 15 20:15:12.208753 2026] [security2:error] [pid 51003:tid 51244] [client 112.86.225.17:40608] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.diggysguide.com"] [uri "/terra/dry-waterhole"] [unique_id "ajCxsMpsKyvb75pkSvZ7rgAAAf4"]
[Mon Jun 15 20:15:12.384123 2026] [security2:error] [pid 51003:tid 51250] [client 213.180.203.250:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxsMpsKyvb75pkSvZ7tAAAAgQ"]
[Mon Jun 15 20:15:12.393612 2026] [security2:error] [pid 51003:tid 51252] [client 213.180.203.250:57328] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxsMpsKyvb75pkSvZ7sAACBjI"]
[Mon Jun 15 20:15:12.413884 2026] [security2:error] [pid 51003:tid 51176] [client 95.108.213.191:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxsMpsKyvb75pkSvZ7tQAAAbo"]
[Mon Jun 15 20:15:12.421451 2026] [security2:error] [pid 51003:tid 51163] [client 95.108.213.191:56892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxsMpsKyvb75pkSvZ7sQABrWg"]
[Mon Jun 15 20:15:12.517362 2026] [security2:error] [pid 51003:tid 51064] [remote 184.107.244.93:50480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.244.107.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cricketrings.com"] [uri "/wp-login.php"] [unique_id "ajCxsMpsKyvb75pkSvZ7uQABnjw"]
[Mon Jun 15 20:15:12.683556 2026] [security2:error] [pid 51003:tid 51067] [remote 184.107.244.93:50480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.244.107.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cricketrings.com"] [uri "/wp-login.php"] [unique_id "ajCxsMpsKyvb75pkSvZ7xAABtj8"], referer: https://cricketrings.com/wp-login.php
[Mon Jun 15 20:15:12.735209 2026] [rewrite:error] [pid 51003:tid 51219] [client 47.79.199.108:42408] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:15:12.818221 2026] [security2:error] [pid 51003:tid 51165] [client 45.84.107.55:33711] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "gamergreatness.com"] [uri "/index.php"] [unique_id "ajCxsMpsKyvb75pkSvZ7wQABr0I"], referer: https://gamergreatness.com/community
[Mon Jun 15 20:15:12.972709 2026] [security2:error] [pid 51003:tid 51227] [client 87.250.224.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxsMpsKyvb75pkSvZ71AAAAe0"]
[Mon Jun 15 20:15:12.979809 2026] [security2:error] [pid 51003:tid 51214] [client 87.250.224.34:33084] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxsMpsKyvb75pkSvZ70AAB4GM"]
[Mon Jun 15 20:15:13.076550 2026] [security2:error] [pid 51003:tid 51158] [client 57.141.14.63:56162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCxsMpsKyvb75pkSvZ71QABqHs"]
[Mon Jun 15 20:15:13.213400 2026] [rewrite:error] [pid 51003:tid 51164] [client 47.79.199.108:42408] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:15:13.385842 2026] [security2:error] [pid 51003:tid 51119] [remote 31.220.84.188:60496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.84.220.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tcspune.in"] [uri "/wp-login.php"] [unique_id "ajCxscpsKyvb75pkSvZ75AABqXM"]
[Mon Jun 15 20:15:13.475397 2026] [security2:error] [pid 51003:tid 51168] [client 95.108.213.223:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxscpsKyvb75pkSvZ76AAAAbI"]
[Mon Jun 15 20:15:13.478543 2026] [security2:error] [pid 51003:tid 51149] [client 95.108.213.223:33182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxscpsKyvb75pkSvZ75gABn3c"]
[Mon Jun 15 20:15:13.565215 2026] [security2:error] [pid 51003:tid 51101] [remote 31.220.84.188:60496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.84.220.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tcspune.in"] [uri "/wp-login.php"] [unique_id "ajCxscpsKyvb75pkSvZ78AAB42E"], referer: https://tcspune.in/wp-login.php
[Mon Jun 15 20:15:14.036675 2026] [rewrite:error] [pid 51003:tid 51020] [remote 47.79.199.103:19834] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:15:14.241936 2026] [security2:error] [pid 51003:tid 51206] [client 95.108.213.192:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxsspsKyvb75pkSvZ8AwAAAdg"]
[Mon Jun 15 20:15:14.249823 2026] [security2:error] [pid 51003:tid 51233] [client 95.108.213.192:35292] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxscpsKyvb75pkSvZ7-AAB8zE"]
[Mon Jun 15 20:15:14.268809 2026] [security2:error] [pid 51003:tid 51173] [client 213.180.203.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxsspsKyvb75pkSvZ8BAAAAbc"]
[Mon Jun 15 20:15:14.272472 2026] [security2:error] [pid 51003:tid 51259] [client 213.180.203.63:39154] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxsspsKyvb75pkSvZ8AAACDWk"]
[Mon Jun 15 20:15:14.328406 2026] [rewrite:error] [pid 51003:tid 51075] [remote 47.79.199.103:19834] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:15:14.505814 2026] [security2:error] [pid 51003:tid 51145] [client 213.180.203.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxsspsKyvb75pkSvZ8FQAAAZs"]
[Mon Jun 15 20:15:14.508851 2026] [security2:error] [pid 51003:tid 51138] [client 213.180.203.9:34534] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxsspsKyvb75pkSvZ8DgABlDA"]
[Mon Jun 15 20:15:14.520714 2026] [security2:error] [pid 51003:tid 51161] [client 57.141.14.97:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aarohiarts.org"] [uri "/index.php"] [unique_id "ajCxsspsKyvb75pkSvZ8CAAAAas"]
[Mon Jun 15 20:15:14.637452 2026] [security2:error] [pid 51003:tid 51204] [client 57.141.14.6:26214] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCxsspsKyvb75pkSvZ8FwAB1l0"]
[Mon Jun 15 20:15:14.645215 2026] [security2:error] [pid 51003:tid 51190] [client 202.76.168.169:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kthemani.com"] [uri "/index.php"] [unique_id "ajCxsMpsKyvb75pkSvZ7yAAByBs"]
[Mon Jun 15 20:15:15.343288 2026] [security2:error] [pid 51003:tid 51233] [client 87.250.224.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxs8psKyvb75pkSvZ8MAAAAfM"]
[Mon Jun 15 20:15:15.350609 2026] [security2:error] [pid 51003:tid 51227] [client 87.250.224.132:35300] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxs8psKyvb75pkSvZ8KQAB7QQ"]
[Mon Jun 15 20:15:15.403426 2026] [security2:error] [pid 51003:tid 51153] [client 31.219.209.201:56984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.209.219.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCxs8psKyvb75pkSvZ8NgAAAaM"]
[Mon Jun 15 20:15:15.403597 2026] [security2:error] [pid 51003:tid 51153] [client 31.219.209.201:56984] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCxs8psKyvb75pkSvZ8NgAAAaM"]
[Mon Jun 15 20:15:15.479342 2026] [security2:error] [pid 51003:tid 51085] [remote 111.225.149.134:12266] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.puzzleadventureguide.com"] [uri "/en/the-prince/travelling-freakshow"] [unique_id "ajCxs8psKyvb75pkSvZ8OwABmVE"]
[Mon Jun 15 20:15:15.585397 2026] [autoindex:error] [pid 51003:tid 51149] [client 43.157.156.190:0] AH01276: Cannot serve directory /home2/zxsmgcmy/public_html/fivekco/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.fivek.co.in
[Mon Jun 15 20:15:15.756993 2026] [security2:error] [pid 51003:tid 51245] [client 5.255.231.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxs8psKyvb75pkSvZ8UAAAAf8"]
[Mon Jun 15 20:15:15.759922 2026] [security2:error] [pid 51003:tid 51252] [client 5.255.231.62:52634] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxs8psKyvb75pkSvZ8SwACBhw"]
[Mon Jun 15 20:15:15.781773 2026] [security2:error] [pid 51003:tid 51209] [client 66.249.79.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sciencecenterrajkot.org"] [uri "/index.php"] [unique_id "ajCxs8psKyvb75pkSvZ8MgAAAds"]
[Mon Jun 15 20:15:15.857577 2026] [security2:error] [pid 51003:tid 51037] [remote 47.128.119.136:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCxs8psKyvb75pkSvZ8NwABqCE"]
[Mon Jun 15 20:15:16.181836 2026] [security2:error] [pid 51003:tid 51254] [client 57.141.14.97:52122] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCxtMpsKyvb75pkSvZ8YAACCD0"]
[Mon Jun 15 20:15:16.182067 2026] [rewrite:error] [pid 51003:tid 51066] [remote 47.79.199.17:22530] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:15:16.244110 2026] [security2:error] [pid 51003:tid 51220] [client 143.244.57.120:42426] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.surveylaya.com"] [uri "/wp-admin/user/"] [unique_id "ajCxtMpsKyvb75pkSvZ8aQAAAeY"]
[Mon Jun 15 20:15:16.337771 2026] [security2:error] [pid 51003:tid 51256] [client 213.180.203.161:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxtMpsKyvb75pkSvZ8bgAAAgo"]
[Mon Jun 15 20:15:16.346481 2026] [security2:error] [pid 51003:tid 51213] [client 213.180.203.161:37664] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxtMpsKyvb75pkSvZ8ZgAB30U"]
[Mon Jun 15 20:15:16.443285 2026] [security2:error] [pid 51003:tid 51212] [client 243.138.119.106:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCxs8psKyvb75pkSvZ8WwAB3mQ"], referer: https://mywordsnthoughts.com/tag/mushroom-curries-side-dishes/page/2/
[Mon Jun 15 20:15:16.447624 2026] [rewrite:error] [pid 51003:tid 51091] [remote 47.79.199.17:22530] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:15:16.453928 2026] [security2:error] [pid 51003:tid 51168] [client 247.135.90.158:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCxs8psKyvb75pkSvZ8XAABsis"], referer: https://mywordsnthoughts.com/tag/mushroom-curries-side-dishes/page/2/
[Mon Jun 15 20:15:16.765632 2026] [security2:error] [pid 51003:tid 51214] [client 87.250.224.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxtMpsKyvb75pkSvZ8hQAAAeA"]
[Mon Jun 15 20:15:16.768666 2026] [security2:error] [pid 51003:tid 51260] [client 87.250.224.229:42970] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxtMpsKyvb75pkSvZ8gwACDgI"]
[Mon Jun 15 20:15:17.086112 2026] [security2:error] [pid 51003:tid 51181] [client 47.79.200.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "societytodaynews.com"] [uri "/index.php"] [unique_id "ajCxtMpsKyvb75pkSvZ8iwAAAb8"], referer: https://www.google.com/
[Mon Jun 15 20:15:17.093664 2026] [security2:error] [pid 51003:tid 51051] [remote 47.128.119.136:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCxtMpsKyvb75pkSvZ8gAACBi8"], referer: https://mywordsnthoughts.com/myworld/category/home-blog/english-blogs/bollywood/page/33/
[Mon Jun 15 20:15:17.138533 2026] [security2:error] [pid 51003:tid 51249] [client 47.128.119.136:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCxtMpsKyvb75pkSvZ8ggACA0o"], referer: https://mywordsnthoughts.com/myworld/category/home-blog/english-blogs/bollywood/page/33/
[Mon Jun 15 20:15:17.156818 2026] [security2:error] [pid 51003:tid 51056] [remote 121.200.216.55:53500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nctindia.org"] [uri "/wp-login.php"] [unique_id "ajCxtcpsKyvb75pkSvZ8kQAB1DQ"]
[Mon Jun 15 20:15:17.165679 2026] [security2:error] [pid 51003:tid 51216] [client 65.111.30.222:42859] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:< ?script|(?:<|< ?/)(?:(?:java|vb)script|about|applet|activex|chrome|qx?ss|embed)|< ?/?i?frame\\\\b)" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1079"] [id "340147"] [rev "141"] [msg "Atomicorp.com WAF Rules: Potential Cross Site Scripting Attack"] [data "<script"] [severity "CRITICAL"] [hostname "www.procrastinatingworker.imcorp.in"] [uri "/"] [unique_id "ajCxtcpsKyvb75pkSvZ8kgAAAeI"]
[Mon Jun 15 20:15:17.198696 2026] [security2:error] [pid 51003:tid 51182] [client 57.141.14.77:35851] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCxtcpsKyvb75pkSvZ8kAABwH0"]
[Mon Jun 15 20:15:17.532353 2026] [security2:error] [pid 51003:tid 51244] [client 202.76.172.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kthemani.com"] [uri "/index.php"] [unique_id "ajCxs8psKyvb75pkSvZ8QAAAAf4"]
[Mon Jun 15 20:15:17.595085 2026] [security2:error] [pid 51003:tid 51024] [remote 121.200.216.55:53500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nctindia.org"] [uri "/wp-login.php"] [unique_id "ajCxtcpsKyvb75pkSvZ8pQABrxQ"], referer: https://nctindia.org/wp-login.php
[Mon Jun 15 20:15:17.865899 2026] [security2:error] [pid 51003:tid 51030] [remote 17.246.19.237:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.19.246.17.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mywordsnthoughts.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ajCxtcpsKyvb75pkSvZ8pwABtBo"], referer: https://mywordsnthoughts.com/sangeetha-sreenivasan-bilingual-writer-translator-of-new-generation/
[Mon Jun 15 20:15:18.286097 2026] [security2:error] [pid 51003:tid 51245] [client 143.244.57.88:60158] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "rkfreshmart.net"] [uri "/wp-admin/network/index.php"] [unique_id "ajCxtcpsKyvb75pkSvZ8qAAAAf8"]
[Mon Jun 15 20:15:18.406629 2026] [rewrite:error] [pid 51003:tid 51067] [remote 47.79.198.97:23970] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:15:18.483080 2026] [security2:error] [pid 51003:tid 51133] [client 143.244.57.88:60158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rkfreshmart.net"] [uri "/wp-login.php"] [unique_id "ajCxtspsKyvb75pkSvZ8vgAAAY8"]
[Mon Jun 15 20:15:18.483181 2026] [security2:error] [pid 51003:tid 51133] [client 143.244.57.88:60158] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rkfreshmart.net"] [uri "/wp-login.php"] [unique_id "ajCxtspsKyvb75pkSvZ8vgAAAY8"]
[Mon Jun 15 20:15:18.631292 2026] [security2:error] [pid 51003:tid 51092] [remote 82.223.68.64:34094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.68.223.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.madanavonz.com"] [uri "/wp-login.php"] [unique_id "ajCxtspsKyvb75pkSvZ8yQAByVg"]
[Mon Jun 15 20:15:18.669968 2026] [rewrite:error] [pid 51003:tid 51046] [remote 47.79.198.97:23970] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:15:18.817839 2026] [security2:error] [pid 51003:tid 51255] [client 5.2.67.226:49924] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "gamergreatness.com"] [uri "/index.php"] [unique_id "ajCxtspsKyvb75pkSvZ8ygACCWM"], referer: https://gamergreatness.com/community/forum/games
[Mon Jun 15 20:15:18.903200 2026] [security2:error] [pid 51003:tid 51010] [remote 82.223.68.64:34094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.68.223.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.madanavonz.com"] [uri "/wp-login.php"] [unique_id "ajCxtspsKyvb75pkSvZ80QACBwY"], referer: https://mail.madanavonz.com/wp-login.php
[Mon Jun 15 20:15:19.301567 2026] [security2:error] [pid 51003:tid 51193] [client 162.214.80.21:39234] ModSecurity: Warning. Matched phrase "Needle" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "prananeedle.com"] [uri "/wp-cron.php"] [unique_id "ajCxt8psKyvb75pkSvZ84wAAAcs"]
[Mon Jun 15 20:15:19.369726 2026] [security2:error] [pid 51003:tid 51123] [remote 177.222.112.154:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.smgl.org"] [uri "/product/wholesale-sterling-silver-rings/mens-rings/418"] [unique_id "ajCxt8psKyvb75pkSvZ85QAB7Xc"], referer: https://www.smgl.org/
[Mon Jun 15 20:15:19.630853 2026] [security2:error] [pid 51003:tid 51186] [client 57.141.14.45:47678] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCxt8psKyvb75pkSvZ86AABxGY"]
[Mon Jun 15 20:15:19.661282 2026] [security2:error] [pid 51003:tid 51069] [remote 34.60.97.204:46048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.97.60.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "softhubtechno.com"] [uri "/Admin/logo/Admin/Admin/logo/Admin/logo/Admin/logo/pms.php"] [unique_id "ajCxt8psKyvb75pkSvZ87AABsUE"]
[Mon Jun 15 20:15:20.557514 2026] [security2:error] [pid 51003:tid 51219] [client 162.214.80.21:52932] ModSecurity: Warning. Matched phrase "Needle" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "prananeedle.com"] [uri "/cgi-sys/404.html"] [unique_id "ajCxuMpsKyvb75pkSvZ9EgAAAeU"]
[Mon Jun 15 20:15:20.785070 2026] [security2:error] [pid 51003:tid 51257] [client 192.140.64.94:29924] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCxuMpsKyvb75pkSvZ9GQAAAgs"]
[Mon Jun 15 20:15:20.785179 2026] [security2:error] [pid 51003:tid 51257] [client 192.140.64.94:29924] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCxuMpsKyvb75pkSvZ9GQAAAgs"]
[Mon Jun 15 20:15:20.972670 2026] [security2:error] [pid 51003:tid 51059] [remote 57.141.14.80:56203] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCxuMpsKyvb75pkSvZ9IAABuDc"]
[Mon Jun 15 20:15:21.058158 2026] [security2:error] [pid 51003:tid 51077] [remote 2a03:2880:f806:9:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ruchini.hemani.finance"] [uri "/index.php"] [unique_id "ajCxuMpsKyvb75pkSvZ9IwACAEk"]
[Mon Jun 15 20:15:21.504067 2026] [security2:error] [pid 51003:tid 51124] [remote 31.24.44.107:44286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.44.24.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "madakasira.in"] [uri "/wp-login.php"] [unique_id "ajCxucpsKyvb75pkSvZ9MQABl3g"]
[Mon Jun 15 20:15:21.733442 2026] [security2:error] [pid 51003:tid 51019] [remote 31.24.44.107:44286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.44.24.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "madakasira.in"] [uri "/wp-login.php"] [unique_id "ajCxucpsKyvb75pkSvZ9PgABmQ8"], referer: https://madakasira.in/wp-login.php
[Mon Jun 15 20:15:21.912411 2026] [security2:error] [pid 51003:tid 51032] [remote 68.178.160.25:39272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "foy.lnh.mybluehostin.me"] [uri "/wp-login.php"] [unique_id "ajCxucpsKyvb75pkSvZ9RwAB5Bw"]
[Mon Jun 15 20:15:22.488707 2026] [security2:error] [pid 51003:tid 51015] [remote 216.73.216.114:38566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "softhubtechno.ehx.czu.mybluehostin.me"] [uri "/Admin/logo/css/images/img/carrer.php"] [unique_id "ajCxuspsKyvb75pkSvZ9ZwABwAs"]
[Mon Jun 15 20:15:22.523766 2026] [security2:error] [pid 51003:tid 51181] [client 57.141.14.72:42177] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCxuspsKyvb75pkSvZ9YgABvz4"]
[Mon Jun 15 20:15:22.656175 2026] [security2:error] [pid 51003:tid 51145] [client 66.249.68.162:0] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "rudrakshwelfare.com"] [uri "/robots.txt"] [unique_id "ajCxuspsKyvb75pkSvZ9cQAAAZs"]
[Mon Jun 15 20:15:23.484039 2026] [security2:error] [pid 51003:tid 51196] [client 47.79.207.97:1202] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "marshitechindia.com"] [uri "/index.php"] [unique_id "ajCxu8psKyvb75pkSvZ9jgAAAc4"], referer: https://www.google.com/
[Mon Jun 15 20:15:23.494730 2026] [security2:error] [pid 51003:tid 51200] [client 104.207.59.194:36917] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "procrastinatingworker.com"] [uri "/index.php"] [unique_id "ajCxu8psKyvb75pkSvZ9qgAAAdI"]
[Mon Jun 15 20:15:23.546547 2026] [security2:error] [pid 51003:tid 51122] [remote 103.239.14.19:36364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.14.239.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.cherubicindia.com"] [uri "/wp-login.php"] [unique_id "ajCxu8psKyvb75pkSvZ9uwABt3Y"]
[Mon Jun 15 20:15:23.920677 2026] [security2:error] [pid 51003:tid 51154] [client 79.139.187.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kthemani.com"] [uri "/index.php"] [unique_id "ajCxuspsKyvb75pkSvZ9TQABpEs"]
[Mon Jun 15 20:15:24.035526 2026] [security2:error] [pid 51003:tid 51112] [remote 57.141.14.102:46957] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCxu8psKyvb75pkSvZ9yAAByGw"]
[Mon Jun 15 20:15:24.052090 2026] [security2:error] [pid 51003:tid 51067] [remote 103.239.14.19:36364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.14.239.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.cherubicindia.com"] [uri "/wp-login.php"] [unique_id "ajCxvMpsKyvb75pkSvZ9ywABtj8"], referer: https://mail.cherubicindia.com/wp-login.php
[Mon Jun 15 20:15:24.348120 2026] [security2:error] [pid 51003:tid 51114] [remote 203.190.11.3:35122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.11.190.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sriramsidd.com"] [uri "/wp-login.php"] [unique_id "ajCxvMpsKyvb75pkSvZ92AAB124"]
[Mon Jun 15 20:15:24.817879 2026] [security2:error] [pid 51003:tid 51086] [remote 242.239.58.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCxvMpsKyvb75pkSvZ93wAB2VI"], referer: https://mywordsnthoughts.com/neeyoru-puzhayay-thazhukumbol-song-from-thilakkam-lyrics-in-english-with-translation/
[Mon Jun 15 20:15:24.869590 2026] [security2:error] [pid 51003:tid 51064] [remote 242.239.58.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCxvMpsKyvb75pkSvZ94gABnTw"], referer: https://mywordsnthoughts.com/neeyoru-puzhayay-thazhukumbol-song-from-thilakkam-lyrics-in-english-with-translation/
[Mon Jun 15 20:15:24.907408 2026] [security2:error] [pid 51003:tid 51076] [remote 203.190.11.3:35122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.11.190.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sriramsidd.com"] [uri "/wp-login.php"] [unique_id "ajCxvMpsKyvb75pkSvZ97gABl0g"], referer: https://sriramsidd.com/wp-login.php
[Mon Jun 15 20:15:25.043574 2026] [security2:error] [pid 51003:tid 51173] [client 104.207.59.194:28765] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "procrastinatingworker.com"] [uri "/index.php"] [unique_id "ajCxvMpsKyvb75pkSvZ97wAAAbc"]
[Mon Jun 15 20:15:25.457810 2026] [security2:error] [pid 51003:tid 51121] [remote 57.141.14.79:62610] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCxvcpsKyvb75pkSvZ9-wABm3U"]
[Mon Jun 15 20:15:25.648676 2026] [rewrite:error] [pid 51003:tid 51142] [client 103.181.74.14:32654] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:15:25.745624 2026] [security2:error] [pid 51003:tid 51241] [client 2a03:2880:f806:3c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ruchini.hemani.finance"] [uri "/index.php"] [unique_id "ajCxvcpsKyvb75pkSvZ-EAAB-zE"]
[Mon Jun 15 20:15:25.883287 2026] [security2:error] [pid 51003:tid 51155] [client 57.141.14.105:34154] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fifthestate.agency"] [uri "/index.php"] [unique_id "ajCxvcpsKyvb75pkSvZ-EgABpUc"]
[Mon Jun 15 20:15:25.920728 2026] [security2:error] [pid 51003:tid 51234] [client 31.219.209.201:57601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.209.219.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCxvcpsKyvb75pkSvZ-GwAAAfQ"]
[Mon Jun 15 20:15:25.920893 2026] [security2:error] [pid 51003:tid 51234] [client 31.219.209.201:57601] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCxvcpsKyvb75pkSvZ-GwAAAfQ"]
[Mon Jun 15 20:15:26.094788 2026] [security2:error] [pid 51003:tid 51068] [remote 64.131.86.2:46906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.86.131.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blogliterati.com"] [uri "/wp-login.php"] [unique_id "ajCxvspsKyvb75pkSvZ-IgAB60A"]
[Mon Jun 15 20:15:26.157735 2026] [security2:error] [pid 51003:tid 51216] [client 95.108.213.136:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxvspsKyvb75pkSvZ-JQAAAeI"]
[Mon Jun 15 20:15:26.160520 2026] [security2:error] [pid 51003:tid 51148] [client 95.108.213.136:59624] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxvspsKyvb75pkSvZ-IQABnjM"]
[Mon Jun 15 20:15:26.266642 2026] [security2:error] [pid 51003:tid 51097] [remote 64.131.86.2:46906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.86.131.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blogliterati.com"] [uri "/wp-login.php"] [unique_id "ajCxvspsKyvb75pkSvZ-KAABo10"], referer: https://blogliterati.com/wp-login.php
[Mon Jun 15 20:15:26.437426 2026] [security2:error] [pid 51003:tid 51195] [client 104.207.59.194:55933] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "procrastinatingworker.com"] [uri "/index.php"] [unique_id "ajCxvspsKyvb75pkSvZ-LQAAAc0"]
[Mon Jun 15 20:15:26.568032 2026] [security2:error] [pid 51003:tid 51093] [remote 116.179.32.98:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.smgl.org"] [uri "/product/925-jewelry/2003-collection/mix-pendants/gempendant6166/"] [unique_id "ajCxvspsKyvb75pkSvZ-NAAB21k"]
[Mon Jun 15 20:15:26.584846 2026] [security2:error] [pid 51003:tid 51189] [client 241.143.35.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCxvspsKyvb75pkSvZ-JwABxyY"], referer: https://mywordsnthoughts.com/tag/mushroom-curries-side-dishes/page/2/
[Mon Jun 15 20:15:27.255345 2026] [security2:error] [pid 51003:tid 51232] [client 95.108.213.101:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxv8psKyvb75pkSvZ-TAAAAfI"]
[Mon Jun 15 20:15:27.256432 2026] [security2:error] [pid 51003:tid 51234] [client 57.141.14.78:33586] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCxv8psKyvb75pkSvZ-RwAB9A4"]
[Mon Jun 15 20:15:27.268460 2026] [security2:error] [pid 51003:tid 51235] [client 95.108.213.101:42464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxv8psKyvb75pkSvZ-RgAB9Rw"]
[Mon Jun 15 20:15:27.504311 2026] [security2:error] [pid 51003:tid 51094] [remote 91.146.102.43:46394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.102.146.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "strategicdarshan.in"] [uri "/wp-login.php"] [unique_id "ajCxv8psKyvb75pkSvZ-WwABzlo"]
[Mon Jun 15 20:15:27.691029 2026] [security2:error] [pid 51003:tid 51135] [client 104.207.59.194:18449] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "procrastinatingworker.com"] [uri "/index.php"] [unique_id "ajCxv8psKyvb75pkSvZ-YAAAAZE"]
[Mon Jun 15 20:15:27.700104 2026] [security2:error] [pid 51003:tid 51145] [client 151.123.176.10:15255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.176.123.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rajunandkardeputycollector.blog"] [uri "/wp-login.php"] [unique_id "ajCxv8psKyvb75pkSvZ-YgAAAZs"], referer: https://rajunandkardeputycollector.blog/wp-login.php
[Mon Jun 15 20:15:27.761057 2026] [security2:error] [pid 51003:tid 51229] [client 91.245.154.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kthemani.com"] [uri "/index.php"] [unique_id "ajCxvcpsKyvb75pkSvZ-GAAAAe8"]
[Mon Jun 15 20:15:27.769953 2026] [security2:error] [pid 51003:tid 51139] [client 47.79.206.165:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "societytodaynews.com"] [uri "/index.php"] [unique_id "ajCxv8psKyvb75pkSvZ-XwAAAZU"], referer: https://www.google.com/
[Mon Jun 15 20:15:27.770477 2026] [security2:error] [pid 51003:tid 51104] [remote 91.146.102.43:46394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.102.146.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "strategicdarshan.in"] [uri "/wp-login.php"] [unique_id "ajCxv8psKyvb75pkSvZ-ZwAB5GQ"], referer: https://strategicdarshan.in/wp-login.php
[Mon Jun 15 20:15:28.154857 2026] [security2:error] [pid 51003:tid 51247] [client 98.147.231.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCxv8psKyvb75pkSvZ-agACAVc"]
[Mon Jun 15 20:15:28.257233 2026] [security2:error] [pid 51003:tid 51147] [client 45.3.36.32:54065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.36.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rajunandkardeputycollector.blog"] [uri "/wp-login.php"] [unique_id "ajCxwMpsKyvb75pkSvZ-ewAAAZ0"], referer: https://rajunandkardeputycollector.blog/wp-login.php
[Mon Jun 15 20:15:28.456062 2026] [security2:error] [pid 51003:tid 51153] [client 213.180.203.158:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxwMpsKyvb75pkSvZ-hAAAAaM"]
[Mon Jun 15 20:15:28.470272 2026] [security2:error] [pid 51003:tid 51233] [client 213.180.203.158:34638] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxwMpsKyvb75pkSvZ-fwAB8wI"]
[Mon Jun 15 20:15:28.630443 2026] [security2:error] [pid 51003:tid 51254] [client 57.141.14.56:42836] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCxwMpsKyvb75pkSvZ-hwACCFU"]
[Mon Jun 15 20:15:28.805660 2026] [security2:error] [pid 51003:tid 51145] [client 104.207.58.176:42897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.58.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rajunandkardeputycollector.blog"] [uri "/wp-login.php"] [unique_id "ajCxwMpsKyvb75pkSvZ-mAAAAZs"], referer: https://rajunandkardeputycollector.blog/wp-login.php
[Mon Jun 15 20:15:29.040981 2026] [security2:error] [pid 51003:tid 51022] [remote 103.127.30.137:49634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.30.127.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rkhomes.org"] [uri "/wp-login.php"] [unique_id "ajCxwcpsKyvb75pkSvZ-nwAB8hI"]
[Mon Jun 15 20:15:29.182682 2026] [security2:error] [pid 51003:tid 51159] [client 95.108.213.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxwcpsKyvb75pkSvZ-pgAAAak"]
[Mon Jun 15 20:15:29.184807 2026] [security2:error] [pid 51003:tid 51142] [client 95.108.213.143:48694] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxwcpsKyvb75pkSvZ-oQABmHY"]
[Mon Jun 15 20:15:29.244344 2026] [security2:error] [pid 51003:tid 51251] [client 57.141.14.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kthemani.com"] [uri "/index.php"] [unique_id "ajCxv8psKyvb75pkSvZ-TgAAAgU"]
[Mon Jun 15 20:15:29.317574 2026] [proxy:error] [pid 51003:tid 51143] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:15:29.317613 2026] [proxy_http:error] [pid 51003:tid 51143] [client 84.17.60.251:36880] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:15:29.318291 2026] [proxy:error] [pid 51003:tid 51143] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:15:29.318338 2026] [proxy_http:error] [pid 51003:tid 51143] [client 84.17.60.251:36880] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:15:29.389161 2026] [security2:error] [pid 51003:tid 51233] [client 65.111.10.167:18743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.10.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rajunandkardeputycollector.blog"] [uri "/wp-login.php"] [unique_id "ajCxwcpsKyvb75pkSvZ-rgAAAfM"], referer: https://rajunandkardeputycollector.blog/wp-login.php
[Mon Jun 15 20:15:29.617103 2026] [proxy:error] [pid 51003:tid 51178] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:15:29.617159 2026] [proxy_http:error] [pid 51003:tid 51178] [client 84.17.60.251:36894] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:15:29.617909 2026] [proxy:error] [pid 51003:tid 51178] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:15:29.617953 2026] [proxy_http:error] [pid 51003:tid 51178] [client 84.17.60.251:36894] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:15:29.622431 2026] [security2:error] [pid 51003:tid 51174] [client 57.141.14.85:29746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCxwcpsKyvb75pkSvZ-twABuFM"]
[Mon Jun 15 20:15:29.746781 2026] [security2:error] [pid 51003:tid 51112] [remote 103.127.30.137:49634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.30.127.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rkhomes.org"] [uri "/wp-login.php"] [unique_id "ajCxwcpsKyvb75pkSvZ-xwAB-2w"], referer: https://rkhomes.org/wp-login.php
[Mon Jun 15 20:15:29.775443 2026] [security2:error] [pid 51003:tid 51137] [client 5.255.231.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxwcpsKyvb75pkSvZ-yAAAAZM"]
[Mon Jun 15 20:15:29.777533 2026] [security2:error] [pid 51003:tid 51152] [client 5.255.231.33:35458] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxwcpsKyvb75pkSvZ-vwABoks"]
[Mon Jun 15 20:15:29.869927 2026] [security2:error] [pid 51003:tid 51252] [client 168.144.82.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "rkhomes.org"] [uri "/index.php"] [unique_id "ajCxwcpsKyvb75pkSvZ-zAAAAgY"], referer: https://rkhomes.org/
[Mon Jun 15 20:15:29.905156 2026] [security2:error] [pid 51003:tid 51167] [client 84.17.60.251:36896] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.buyndrive.in"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ajCxwcpsKyvb75pkSvZ-zwAAAbE"]
[Mon Jun 15 20:15:29.968190 2026] [security2:error] [pid 51003:tid 51155] [client 104.207.51.214:46497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.51.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rajunandkardeputycollector.blog"] [uri "/wp-login.php"] [unique_id "ajCxwcpsKyvb75pkSvZ-0QAAAaU"], referer: https://rajunandkardeputycollector.blog/wp-login.php
[Mon Jun 15 20:15:30.231046 2026] [security2:error] [pid 51003:tid 51147] [client 47.79.205.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "societytodaynews.com"] [uri "/index.php"] [unique_id "ajCxwspsKyvb75pkSvZ-1gAAAZ0"], referer: https://www.google.com/
[Mon Jun 15 20:15:30.248714 2026] [security2:error] [pid 51003:tid 51181] [client 84.17.60.251:36910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.60.17.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.buyndrive.in"] [uri "/xmlrpc.php"] [unique_id "ajCxwspsKyvb75pkSvZ-5AAAAb8"]
[Mon Jun 15 20:15:30.254880 2026] [security2:error] [pid 51003:tid 51214] [client 213.180.203.167:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxwspsKyvb75pkSvZ-5gAAAeA"]
[Mon Jun 15 20:15:30.269498 2026] [security2:error] [pid 51003:tid 51235] [client 213.180.203.167:54946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxwspsKyvb75pkSvZ-3QAB9Rk"]
[Mon Jun 15 20:15:30.547248 2026] [proxy:error] [pid 51003:tid 51200] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:15:30.547333 2026] [proxy_http:error] [pid 51003:tid 51200] [client 84.17.60.251:36918] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:15:30.548246 2026] [proxy:error] [pid 51003:tid 51200] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:15:30.548280 2026] [proxy_http:error] [pid 51003:tid 51200] [client 84.17.60.251:36918] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:15:30.713712 2026] [security2:error] [pid 51003:tid 51179] [client 116.179.32.34:12735] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "spiritedblogger.com"] [uri "/index.php"] [unique_id "ajCxwcpsKyvb75pkSvZ-swABvWU"]
[Mon Jun 15 20:15:30.853902 2026] [security2:error] [pid 51003:tid 51193] [client 84.17.60.251:36930] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.buyndrive.in"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ajCxwspsKyvb75pkSvZ_AQAAAcs"]
[Mon Jun 15 20:15:30.973487 2026] [security2:error] [pid 51003:tid 51216] [client 192.140.64.94:29845] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCxwspsKyvb75pkSvZ_BgAAAeI"]
[Mon Jun 15 20:15:30.980050 2026] [security2:error] [pid 51003:tid 51216] [client 192.140.64.94:29845] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCxwspsKyvb75pkSvZ_BgAAAeI"]
[Mon Jun 15 20:15:31.036294 2026] [security2:error] [pid 51003:tid 51240] [client 95.108.213.213:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxwspsKyvb75pkSvZ_BwAAAfo"]
[Mon Jun 15 20:15:31.037735 2026] [security2:error] [pid 51003:tid 51141] [client 95.108.213.213:47306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxwspsKyvb75pkSvZ-_gABl0g"]
[Mon Jun 15 20:15:31.147688 2026] [security2:error] [pid 51003:tid 51213] [client 84.17.60.251:36946] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.buyndrive.in"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ajCxw8psKyvb75pkSvZ_DgAAAd8"]
[Mon Jun 15 20:15:31.253351 2026] [security2:error] [pid 51003:tid 51205] [client 213.180.203.137:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxw8psKyvb75pkSvZ_EAAAAdc"]
[Mon Jun 15 20:15:31.267192 2026] [security2:error] [pid 51003:tid 51121] [remote 184.107.244.93:41212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.244.107.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.blackhorsespac.com"] [uri "/wp-login.php"] [unique_id "ajCxw8psKyvb75pkSvZ_EwABynU"]
[Mon Jun 15 20:15:31.272474 2026] [security2:error] [pid 51003:tid 51165] [client 213.180.203.137:57052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxw8psKyvb75pkSvZ_CwABr38"]
[Mon Jun 15 20:15:31.446084 2026] [security2:error] [pid 51003:tid 51243] [client 84.17.60.251:36948] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.buyndrive.in"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ajCxw8psKyvb75pkSvZ_GgAAAf0"]
[Mon Jun 15 20:15:31.515098 2026] [security2:error] [pid 51003:tid 51134] [client 39.33.178.40:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.vernes.co.uk"] [uri "/"] [unique_id "ajCxw8psKyvb75pkSvZ_IAAAAZA"]
[Mon Jun 15 20:15:31.534692 2026] [security2:error] [pid 51003:tid 51222] [client 57.141.14.31:33380] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCxw8psKyvb75pkSvZ_GAAB6HQ"]
[Mon Jun 15 20:15:31.543606 2026] [security2:error] [pid 51003:tid 51109] [remote 184.107.244.93:41212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.244.107.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.blackhorsespac.com"] [uri "/wp-login.php"] [unique_id "ajCxw8psKyvb75pkSvZ_IgAB5mk"], referer: https://mail.blackhorsespac.com/wp-login.php
[Mon Jun 15 20:15:31.674400 2026] [security2:error] [pid 51003:tid 51227] [client 5.255.231.114:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxw8psKyvb75pkSvZ_JgAAAe0"]
[Mon Jun 15 20:15:31.715018 2026] [security2:error] [pid 51003:tid 51164] [client 5.255.231.114:60776] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxw8psKyvb75pkSvZ_IwABrkc"]
[Mon Jun 15 20:15:31.743064 2026] [security2:error] [pid 51003:tid 51175] [client 84.17.60.251:36954] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.buyndrive.in"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "ajCxw8psKyvb75pkSvZ_LAAAAbk"]
[Mon Jun 15 20:15:31.869435 2026] [security2:error] [pid 51003:tid 51204] [client 145.14.143.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCxw8psKyvb75pkSvZ_FwAB1gg"], referer: https://mywordsnthoughts.com/myworld/a-return-journey-to-the-nostalgic-days-of-ration-shops-ration-kada/
[Mon Jun 15 20:15:31.873415 2026] [security2:error] [pid 51003:tid 51241] [client 145.14.143.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCxw8psKyvb75pkSvZ_GQAB-3c"], referer: https://mywordsnthoughts.com/myworld/a-return-journey-to-the-nostalgic-days-of-ration-shops-ration-kada/
[Mon Jun 15 20:15:31.907945 2026] [security2:error] [pid 51003:tid 51085] [remote 139.59.150.41:44944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.150.59.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "theelitecreations.com"] [uri "/wp-login.php"] [unique_id "ajCxw8psKyvb75pkSvZ_TQAB_VE"]
[Mon Jun 15 20:15:31.945901 2026] [security2:error] [pid 51003:tid 51180] [client 45.170.65.126:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kthemani.com"] [uri "/index.php"] [unique_id "ajCxwcpsKyvb75pkSvZ-0gABvh8"]
[Mon Jun 15 20:15:32.032789 2026] [security2:error] [pid 51003:tid 51140] [client 57.141.14.82:53476] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCxw8psKyvb75pkSvZ_TgABlg8"]
[Mon Jun 15 20:15:32.040962 2026] [security2:error] [pid 51003:tid 51230] [client 84.17.60.251:36960] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.buyndrive.in"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ajCxxMpsKyvb75pkSvZ_WQAAAfA"]
[Mon Jun 15 20:15:32.200317 2026] [security2:error] [pid 51003:tid 51176] [client 95.108.213.209:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxxMpsKyvb75pkSvZ_ZQAAAbo"]
[Mon Jun 15 20:15:32.240777 2026] [security2:error] [pid 51003:tid 51253] [client 95.108.213.209:48798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxxMpsKyvb75pkSvZ_XgACBwM"]
[Mon Jun 15 20:15:32.375383 2026] [security2:error] [pid 51003:tid 51204] [client 84.17.60.251:36966] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.buyndrive.in"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "ajCxxMpsKyvb75pkSvZ_bgAAAdY"]
[Mon Jun 15 20:15:32.487298 2026] [proxy:error] [pid 51003:tid 51058] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:15:32.487357 2026] [proxy_http:error] [pid 51003:tid 51058] [remote 51.81.245.138:33740] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:15:32.488287 2026] [proxy:error] [pid 51003:tid 51058] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:15:32.488335 2026] [proxy_http:error] [pid 51003:tid 51058] [remote 51.81.245.138:33740] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:15:32.522716 2026] [autoindex:error] [pid 51003:tid 51025] [remote 51.81.245.138:33752] AH01276: Cannot serve directory /home1/rugqjjmy/public_html/everestindgrp/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:15:32.666946 2026] [security2:error] [pid 51003:tid 51145] [client 84.17.60.251:36970] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.buyndrive.in"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "ajCxxMpsKyvb75pkSvZ_egAAAZs"]
[Mon Jun 15 20:15:32.728183 2026] [security2:error] [pid 51003:tid 51219] [client 104.207.59.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "procrastinatingworker.com"] [uri "/index.php"] [unique_id "ajCxxMpsKyvb75pkSvZ_dwAAAeU"]
[Mon Jun 15 20:15:32.739688 2026] [security2:error] [pid 51003:tid 51157] [client 5.255.231.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxxMpsKyvb75pkSvZ_ewAAAac"]
[Mon Jun 15 20:15:32.784364 2026] [security2:error] [pid 51003:tid 51242] [client 5.255.231.116:47352] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxxMpsKyvb75pkSvZ_dAAB_GQ"]
[Mon Jun 15 20:15:32.969378 2026] [security2:error] [pid 51003:tid 51207] [client 84.17.60.251:36980] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.buyndrive.in"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ajCxxMpsKyvb75pkSvZ_ggAAAdk"]
[Mon Jun 15 20:15:33.078495 2026] [security2:error] [pid 51003:tid 51256] [client 110.249.202.120:50450] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mahavirgems.co.in"] [uri "/robots.txt"] [unique_id "ajCxxcpsKyvb75pkSvZ_gwAAAgo"]
[Mon Jun 15 20:15:33.267552 2026] [security2:error] [pid 51003:tid 51135] [client 84.17.60.251:36986] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.buyndrive.in"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ajCxxcpsKyvb75pkSvZ_igAAAZE"]
[Mon Jun 15 20:15:33.289277 2026] [security2:error] [pid 51003:tid 51233] [client 54.176.66.62:56294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spiritedblogger.com"] [uri "/index.php"] [unique_id "ajCxxcpsKyvb75pkSvZ_hQAAAfM"]
[Mon Jun 15 20:15:33.323471 2026] [security2:error] [pid 51003:tid 51198] [client 54.176.66.62:54376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spiritedblogger.com"] [uri "/index.php"] [unique_id "ajCxxcpsKyvb75pkSvZ_iAAAAdA"]
[Mon Jun 15 20:15:33.433787 2026] [security2:error] [pid 51003:tid 51192] [client 213.180.203.101:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxxcpsKyvb75pkSvZ_lAAAAco"]
[Mon Jun 15 20:15:33.453122 2026] [security2:error] [pid 51003:tid 51139] [client 213.180.203.101:44876] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxxcpsKyvb75pkSvZ_jgABlWc"]
[Mon Jun 15 20:15:33.588970 2026] [security2:error] [pid 51003:tid 51137] [client 84.17.60.251:36996] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.buyndrive.in"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ajCxxcpsKyvb75pkSvZ_ngAAAZM"]
[Mon Jun 15 20:15:33.677998 2026] [security2:error] [pid 51003:tid 51222] [client 5.255.231.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxxcpsKyvb75pkSvZ_ogAAAeg"]
[Mon Jun 15 20:15:33.720899 2026] [security2:error] [pid 51003:tid 51205] [client 5.255.231.194:49866] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxxcpsKyvb75pkSvZ_nQAB1zg"]
[Mon Jun 15 20:15:33.893242 2026] [security2:error] [pid 51003:tid 51191] [client 84.17.60.251:37004] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.buyndrive.in"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ajCxxcpsKyvb75pkSvZ_rgAAAck"]
[Mon Jun 15 20:15:34.175377 2026] [security2:error] [pid 51003:tid 51214] [client 84.17.60.251:37014] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.buyndrive.in"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "ajCxxspsKyvb75pkSvZ_uAAAAeA"]
[Mon Jun 15 20:15:34.254375 2026] [security2:error] [pid 51003:tid 51030] [remote 52.167.144.197:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mywordsnthoughts.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ajCxxspsKyvb75pkSvZ_vgABkho"], referer: https://mywordsnthoughts.com/dust-allergy-sneezing-a-few-useful-tips-to-get-rid-of-them/
[Mon Jun 15 20:15:34.259113 2026] [security2:error] [pid 51003:tid 51087] [remote 17.246.23.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.23.246.17.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mywordsnthoughts.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ajCxxspsKyvb75pkSvZ_uwABo1M"], referer: https://mywordsnthoughts.com/paul-sabu-is-considered-one-of-the-top-aor-musicians-of-all-time/
[Mon Jun 15 20:15:34.339221 2026] [security2:error] [pid 51003:tid 51252] [client 57.141.14.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aarohiarts.org"] [uri "/index.php"] [unique_id "ajCxxspsKyvb75pkSvZ_swAAAgY"]
[Mon Jun 15 20:15:34.421121 2026] [security2:error] [pid 51003:tid 51067] [remote 57.141.14.56:42866] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCxxspsKyvb75pkSvZ_wwABpT8"]
[Mon Jun 15 20:15:34.461864 2026] [security2:error] [pid 51003:tid 51137] [client 84.17.60.251:37016] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.buyndrive.in"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "ajCxxspsKyvb75pkSvZ_ygAAAZM"]
[Mon Jun 15 20:15:34.473170 2026] [security2:error] [pid 51003:tid 51111] [remote 173.236.215.92:53390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.215.236.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fifthestate.agency"] [uri "/wp-login.php"] [unique_id "ajCxxspsKyvb75pkSvZ_yQABqms"]
[Mon Jun 15 20:15:34.545119 2026] [security2:error] [pid 51003:tid 51222] [client 95.108.213.214:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxxspsKyvb75pkSvZ_zAAAAeg"]
[Mon Jun 15 20:15:34.547931 2026] [security2:error] [pid 51003:tid 51183] [client 95.108.213.214:57018] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxxspsKyvb75pkSvZ_yAABwV4"]
[Mon Jun 15 20:15:34.745227 2026] [security2:error] [pid 51003:tid 51167] [client 84.17.60.251:37026] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.buyndrive.in"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ajCxxspsKyvb75pkSvZ_1gAAAbE"]
[Mon Jun 15 20:15:34.842277 2026] [security2:error] [pid 51003:tid 51049] [remote 176.129.57.20:56189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.57.129.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "efficpro.com"] [uri "/wp-login.php"] [unique_id "ajCxxspsKyvb75pkSvZ_2AACCS0"]
[Mon Jun 15 20:15:34.995082 2026] [security2:error] [pid 51003:tid 51103] [remote 52.167.144.197:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mywordsnthoughts.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ajCxxspsKyvb75pkSvZ_5QACCmM"], referer: https://mywordsnthoughts.com/carrot-paripp-chapati-carrot-dal-chapati/
[Mon Jun 15 20:15:35.060097 2026] [security2:error] [pid 51003:tid 51108] [remote 69.57.172.207:56516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.172.57.69.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wafflemenu.onl"] [uri "/wp-login.php"] [unique_id "ajCxx8psKyvb75pkSvZ_5wACBWg"]
[Mon Jun 15 20:15:35.073135 2026] [security2:error] [pid 51003:tid 51173] [client 95.108.213.237:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxx8psKyvb75pkSvZ_5gAAAbc"]
[Mon Jun 15 20:15:35.085161 2026] [security2:error] [pid 51003:tid 51197] [client 95.108.213.237:45984] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxxspsKyvb75pkSvZ_4AABzyI"]
[Mon Jun 15 20:15:35.086085 2026] [security2:error] [pid 51003:tid 51135] [client 84.17.60.251:37042] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.buyndrive.in"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ajCxx8psKyvb75pkSvZ_6gAAAZE"]
[Mon Jun 15 20:15:35.186944 2026] [security2:error] [pid 51003:tid 51046] [remote 176.129.57.20:56189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.57.129.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "efficpro.com"] [uri "/wp-login.php"] [unique_id "ajCxx8psKyvb75pkSvZ_7wABuyo"], referer: https://efficpro.com/wp-login.php
[Mon Jun 15 20:15:35.379337 2026] [security2:error] [pid 51003:tid 51224] [client 84.17.60.251:37058] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.buyndrive.in"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "ajCxx8psKyvb75pkSvZ_-gAAAeo"]
[Mon Jun 15 20:15:35.568872 2026] [security2:error] [pid 51003:tid 51027] [remote 69.57.172.207:56516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.172.57.69.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wafflemenu.onl"] [uri "/wp-login.php"] [unique_id "ajCxx8psKyvb75pkSvaABwACDRc"], referer: https://wafflemenu.onl/wp-login.php
[Mon Jun 15 20:15:35.613591 2026] [security2:error] [pid 51003:tid 51223] [client 95.108.213.136:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxx8psKyvb75pkSvaACAAAAek"]
[Mon Jun 15 20:15:35.619028 2026] [security2:error] [pid 51003:tid 51196] [client 95.108.213.136:40346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxx8psKyvb75pkSvaAAwABzkg"]
[Mon Jun 15 20:15:35.633496 2026] [security2:error] [pid 51003:tid 51220] [client 2a03:2880:f806:17:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ruchini.hemani.finance"] [uri "/index.php"] [unique_id "ajCxx8psKyvb75pkSvaAAAAB5jo"]
[Mon Jun 15 20:15:36.204841 2026] [security2:error] [pid 51003:tid 51166] [client 95.108.213.101:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxyMpsKyvb75pkSvaAHgAAAbA"]
[Mon Jun 15 20:15:36.206577 2026] [security2:error] [pid 51003:tid 51178] [client 95.108.213.101:58150] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxyMpsKyvb75pkSvaAHAABvA0"]
[Mon Jun 15 20:15:36.424616 2026] [security2:error] [pid 51003:tid 51256] [client 31.219.209.201:58207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.209.219.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCxyMpsKyvb75pkSvaAJwAAAgo"]
[Mon Jun 15 20:15:36.424744 2026] [security2:error] [pid 51003:tid 51256] [client 31.219.209.201:58207] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCxyMpsKyvb75pkSvaAJwAAAgo"]
[Mon Jun 15 20:15:36.586733 2026] [security2:error] [pid 51003:tid 51180] [client 104.207.59.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "procrastinatingworker.com"] [uri "/index.php"] [unique_id "ajCxyMpsKyvb75pkSvaAKwAAAb4"]
[Mon Jun 15 20:15:36.636543 2026] [security2:error] [pid 51003:tid 51072] [remote 103.127.30.137:41554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.30.127.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aadarshengineers.com"] [uri "/wp-login.php"] [unique_id "ajCxyMpsKyvb75pkSvaAOAACB0Q"]
[Mon Jun 15 20:15:36.661342 2026] [security2:error] [pid 51003:tid 51187] [client 213.180.203.158:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxyMpsKyvb75pkSvaANwAAAcU"]
[Mon Jun 15 20:15:36.663673 2026] [security2:error] [pid 51003:tid 51158] [client 213.180.203.158:59508] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxyMpsKyvb75pkSvaAMwABqEY"]
[Mon Jun 15 20:15:36.769553 2026] [security2:error] [pid 51003:tid 51214] [client 177.200.143.92:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kthemani.com"] [uri "/index.php"] [unique_id "ajCxxspsKyvb75pkSvZ_2wAAAeA"]
[Mon Jun 15 20:15:37.053146 2026] [security2:error] [pid 51003:tid 51171] [client 43.156.36.214:47258] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggermint.com"] [uri "/index.php"] [unique_id "ajCxyMpsKyvb75pkSvaASAAAAbU"]
[Mon Jun 15 20:15:37.058659 2026] [security2:error] [pid 51003:tid 51143] [client 43.156.36.214:47242] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggermint.com"] [uri "/index.php"] [unique_id "ajCxyMpsKyvb75pkSvaASQAAAZk"]
[Mon Jun 15 20:15:37.108507 2026] [security2:error] [pid 51003:tid 51040] [remote 103.127.30.137:41554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.30.127.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aadarshengineers.com"] [uri "/wp-login.php"] [unique_id "ajCxycpsKyvb75pkSvaATgABsCQ"], referer: https://aadarshengineers.com/wp-login.php
[Mon Jun 15 20:15:37.239847 2026] [security2:error] [pid 51003:tid 51178] [client 65.111.30.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.procrastinatingworker.imcorp.in"] [uri "/index.php"] [unique_id "ajCxycpsKyvb75pkSvaAUAAAAbw"]
[Mon Jun 15 20:15:37.494083 2026] [security2:error] [pid 51003:tid 51031] [remote 57.141.14.41:38677] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCxycpsKyvb75pkSvaAWAABqRs"]
[Mon Jun 15 20:15:37.515575 2026] [security2:error] [pid 51003:tid 51019] [remote 89.58.31.106:54250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.31.58.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "editonmedia.com"] [uri "/wp-login.php"] [unique_id "ajCxycpsKyvb75pkSvaAXwABvQ8"]
[Mon Jun 15 20:15:37.746612 2026] [security2:error] [pid 51003:tid 51096] [remote 89.58.31.106:54250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.31.58.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "editonmedia.com"] [uri "/wp-login.php"] [unique_id "ajCxycpsKyvb75pkSvaAbwAB51w"], referer: https://editonmedia.com/wp-login.php
[Mon Jun 15 20:15:37.812923 2026] [security2:error] [pid 51003:tid 51154] [client 43.156.36.214:47278] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggermint.com"] [uri "/index.php"] [unique_id "ajCxycpsKyvb75pkSvaAbgAAAaQ"]
[Mon Jun 15 20:15:37.856442 2026] [security2:error] [pid 51003:tid 51182] [client 43.156.36.214:47264] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggermint.com"] [uri "/index.php"] [unique_id "ajCxycpsKyvb75pkSvaAcAAAAcA"]
[Mon Jun 15 20:15:37.982937 2026] [security2:error] [pid 51003:tid 51250] [client 194.15.36.117:35458] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "gamergreatness.com"] [uri "/index.php"] [unique_id "ajCxycpsKyvb75pkSvaAagACBBw"], referer: https://gamergreatness.com/community/forum/general-gaming
[Mon Jun 15 20:15:38.165345 2026] [security2:error] [pid 51003:tid 51148] [client 47.79.200.212:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "societytodaynews.com"] [uri "/index.php"] [unique_id "ajCxycpsKyvb75pkSvaAeQAAAZ4"], referer: https://www.google.com/
[Mon Jun 15 20:15:38.301599 2026] [security2:error] [pid 51003:tid 51084] [remote 176.61.149.165:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.149.61.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ewmr.global"] [uri "/wp-login.php"] [unique_id "ajCxyspsKyvb75pkSvaAiAABvlA"]
[Mon Jun 15 20:15:38.566316 2026] [security2:error] [pid 51003:tid 51056] [remote 176.61.149.165:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.149.61.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ewmr.global"] [uri "/wp-login.php"] [unique_id "ajCxyspsKyvb75pkSvaAoAABmzQ"], referer: https://ewmr.global/wp-login.php
[Mon Jun 15 20:15:38.622735 2026] [security2:error] [pid 51003:tid 51214] [client 57.141.14.44:54085] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCxyspsKyvb75pkSvaAmwAB4Dg"]
[Mon Jun 15 20:15:39.016414 2026] [security2:error] [pid 51003:tid 51148] [client 143.244.57.88:38348] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "rkfreshmart.net"] [uri "/wp-admin/user/"] [unique_id "ajCxy8psKyvb75pkSvaAtgAAAZ4"]
[Mon Jun 15 20:15:39.254064 2026] [security2:error] [pid 51003:tid 51245] [client 143.244.57.120:41934] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "www.surveylaya.com"] [uri "/wp-admin/user/index.php"] [unique_id "ajCxyspsKyvb75pkSvaApgAAAf8"]
[Mon Jun 15 20:15:39.406833 2026] [security2:error] [pid 51003:tid 51182] [client 84.21.190.140:4460] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "neeveducationfoundation.org"] [uri "/wp-content/plugins/mainwp-child/readme.txt"] [unique_id "ajCxy8psKyvb75pkSvaAywAAAcA"]
[Mon Jun 15 20:15:39.434384 2026] [security2:error] [pid 51003:tid 51236] [client 143.244.57.120:41934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.surveylaya.com"] [uri "/wp-login.php"] [unique_id "ajCxy8psKyvb75pkSvaAzQAAAfY"]
[Mon Jun 15 20:15:39.434527 2026] [security2:error] [pid 51003:tid 51236] [client 143.244.57.120:41934] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.surveylaya.com"] [uri "/wp-login.php"] [unique_id "ajCxy8psKyvb75pkSvaAzQAAAfY"]
[Mon Jun 15 20:15:39.447269 2026] [security2:error] [pid 51003:tid 51115] [remote 40.77.167.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCxyspsKyvb75pkSvaArwABlW8"]
[Mon Jun 15 20:15:39.618832 2026] [security2:error] [pid 51003:tid 51150] [client 195.63.31.182:58007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.31.63.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rajunandkardeputycollector.blog"] [uri "/wp-login.php"] [unique_id "ajCxy8psKyvb75pkSvaA0QAAAaA"], referer: https://rajunandkardeputycollector.blog/wp-login.php
[Mon Jun 15 20:15:39.643440 2026] [security2:error] [pid 51003:tid 51186] [client 190.89.30.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kthemani.com"] [uri "/index.php"] [unique_id "ajCxycpsKyvb75pkSvaAYwABxCM"]
[Mon Jun 15 20:15:39.661502 2026] [security2:error] [pid 51003:tid 51111] [remote 2a03:2880:f806:25:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ruchini.hemani.finance"] [uri "/index.php"] [unique_id "ajCxy8psKyvb75pkSvaA0AAB-Ws"]
[Mon Jun 15 20:15:39.799207 2026] [security2:error] [pid 51003:tid 51114] [remote 74.7.227.173:55300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.rentswale.ehx.czu.mybluehostin.me"] [uri "/fonts/images/js/images/admin/uploads/icon/css/img/subcategory.php"] [unique_id "ajCxy8psKyvb75pkSvaA3QAB0G4"], referer: https://www.rentswale.ehx.czu.mybluehostin.me/fonts/images/js/images/admin/uploads/icon/css/img/maestro.png
[Mon Jun 15 20:15:39.871340 2026] [security2:error] [pid 51003:tid 51177] [client 45.61.184.21:39114] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "leafsdiary.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ajCxy8psKyvb75pkSvaA5QAAAbs"]
[Mon Jun 15 20:15:40.323551 2026] [security2:error] [pid 51003:tid 51149] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ewmr.global"] [uri "/index.php"] [unique_id "ajCxyspsKyvb75pkSvaAgwABnyw"]
[Mon Jun 15 20:15:40.381056 2026] [security2:error] [pid 51003:tid 51086] [remote 114.119.141.203:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mywordsnthoughts.com"] [uri "/myworld/women-zone/how-to-remove-stains-from-clothes-a-few-simple-tips/"] [unique_id "ajCxzMpsKyvb75pkSvaA9AAB71I"], referer: http://mywordsnthoughts.com/myworld/womens-zone-index/dress-care-tips
[Mon Jun 15 20:15:40.396779 2026] [security2:error] [pid 51003:tid 51221] [client 57.141.14.3:22762] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCxzMpsKyvb75pkSvaA8gAB5yI"]
[Mon Jun 15 20:15:40.741720 2026] [security2:error] [pid 51003:tid 51164] [client 45.61.184.21:39354] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "leafsdiary.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ajCxzMpsKyvb75pkSvaBCwAAAa4"]
[Mon Jun 15 20:15:40.828603 2026] [security2:error] [pid 51003:tid 51147] [client 95.108.213.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxzMpsKyvb75pkSvaBDgAAAZ0"]
[Mon Jun 15 20:15:40.835566 2026] [security2:error] [pid 51003:tid 51166] [client 95.108.213.143:46724] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxzMpsKyvb75pkSvaBCAABsHM"]
[Mon Jun 15 20:15:41.433370 2026] [security2:error] [pid 51003:tid 51167] [client 192.140.64.94:29723] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCxzcpsKyvb75pkSvaBKwAAAbE"]
[Mon Jun 15 20:15:41.433534 2026] [security2:error] [pid 51003:tid 51167] [client 192.140.64.94:29723] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCxzcpsKyvb75pkSvaBKwAAAbE"]
[Mon Jun 15 20:15:41.649431 2026] [security2:error] [pid 51003:tid 51068] [remote 57.141.14.63:28066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCxzcpsKyvb75pkSvaBNAAB5UA"]
[Mon Jun 15 20:15:41.679304 2026] [security2:error] [pid 51003:tid 51135] [client 5.255.231.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxzcpsKyvb75pkSvaBOgAAAZE"]
[Mon Jun 15 20:15:41.681958 2026] [security2:error] [pid 51003:tid 51222] [client 5.255.231.33:51756] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxzcpsKyvb75pkSvaBNwAB6Hc"]
[Mon Jun 15 20:15:42.180024 2026] [security2:error] [pid 51003:tid 51238] [client 213.180.203.167:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxzspsKyvb75pkSvaBUAAAAfg"]
[Mon Jun 15 20:15:42.200787 2026] [security2:error] [pid 51003:tid 51197] [client 213.180.203.167:35856] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxzspsKyvb75pkSvaBTQABz08"]
[Mon Jun 15 20:15:42.453084 2026] [security2:error] [pid 51003:tid 51203] [client 34.91.129.93:40960] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "autodiscover.craftliquors.in"] [uri "/"] [unique_id "ajCxzspsKyvb75pkSvaBXwAAAdU"]
[Mon Jun 15 20:15:42.453188 2026] [security2:error] [pid 51003:tid 51203] [client 34.91.129.93:40960] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "autodiscover.craftliquors.in"] [uri "/"] [unique_id "ajCxzspsKyvb75pkSvaBXwAAAdU"]
[Mon Jun 15 20:15:42.530995 2026] [security2:error] [pid 51003:tid 51210] [client 66.249.68.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.samanvaycommunications.com"] [uri "/index.php"] [unique_id "ajCxzcpsKyvb75pkSvaBMwAAAdw"]
[Mon Jun 15 20:15:42.724920 2026] [security2:error] [pid 51003:tid 51033] [remote 154.127.86.8:57546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.86.127.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "inspirethenation.in"] [uri "/wp-login.php"] [unique_id "ajCxzspsKyvb75pkSvaBagABqh0"]
[Mon Jun 15 20:15:42.731428 2026] [security2:error] [pid 51003:tid 51099] [remote 213.32.22.52:54668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.22.32.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "homampoojas.com"] [uri "/wp-login.php"] [unique_id "ajCxzspsKyvb75pkSvaBaQABvl8"]
[Mon Jun 15 20:15:42.800483 2026] [security2:error] [pid 51003:tid 51206] [client 85.204.70.104:36514] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.hotelgrandpalacecbe.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ajCxzspsKyvb75pkSvaBcQAAAdg"]
[Mon Jun 15 20:15:42.857976 2026] [security2:error] [pid 51003:tid 51199] [client 95.108.213.213:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxzspsKyvb75pkSvaBcgAAAdE"]
[Mon Jun 15 20:15:42.860063 2026] [security2:error] [pid 51003:tid 51251] [client 95.108.213.213:60540] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxzspsKyvb75pkSvaBbwACBUw"]
[Mon Jun 15 20:15:42.942201 2026] [security2:error] [pid 51003:tid 51031] [remote 213.32.22.52:54668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.22.32.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "homampoojas.com"] [uri "/wp-login.php"] [unique_id "ajCxzspsKyvb75pkSvaBdQABqxs"], referer: https://homampoojas.com/wp-login.php
[Mon Jun 15 20:15:43.104662 2026] [security2:error] [pid 51003:tid 51191] [client 57.141.14.64:62718] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCxzspsKyvb75pkSvaBeAAByQ8"]
[Mon Jun 15 20:15:43.350528 2026] [security2:error] [pid 51003:tid 51139] [client 85.204.70.104:36520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.hotelgrandpalacecbe.com"] [uri "/xmlrpc.php"] [unique_id "ajCxz8psKyvb75pkSvaBhwAAAZU"]
[Mon Jun 15 20:15:43.410700 2026] [security2:error] [pid 51003:tid 51007] [remote 154.127.86.8:57546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.86.127.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "inspirethenation.in"] [uri "/wp-login.php"] [unique_id "ajCxz8psKyvb75pkSvaBjQACAQM"], referer: https://inspirethenation.in/wp-login.php
[Mon Jun 15 20:15:43.436715 2026] [security2:error] [pid 51003:tid 51194] [client 213.180.203.137:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxz8psKyvb75pkSvaBjwAAAcw"]
[Mon Jun 15 20:15:43.452252 2026] [security2:error] [pid 51003:tid 51246] [client 213.180.203.137:55860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxz8psKyvb75pkSvaBiQACADM"]
[Mon Jun 15 20:15:43.796779 2026] [security2:error] [pid 51003:tid 51179] [client 47.79.199.60:7912] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.diggysguide.com"] [uri "/index.php"] [unique_id "ajCxz8psKyvb75pkSvaBpgAAAb0"]
[Mon Jun 15 20:15:43.938855 2026] [security2:error] [pid 51003:tid 51229] [client 5.255.231.114:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxz8psKyvb75pkSvaBrQAAAe8"]
[Mon Jun 15 20:15:43.949397 2026] [security2:error] [pid 51003:tid 51232] [client 5.255.231.114:35302] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCxz8psKyvb75pkSvaBqwAB8is"]
[Mon Jun 15 20:15:44.082374 2026] [security2:error] [pid 51003:tid 51201] [client 74.220.48.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cleantech-holdings.us"] [uri "/index.php"] [unique_id "ajCxz8psKyvb75pkSvaBqQAAAdM"]
[Mon Jun 15 20:15:44.227052 2026] [security2:error] [pid 51003:tid 51256] [client 190.129.101.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kthemani.com"] [uri "/index.php"] [unique_id "ajCxzspsKyvb75pkSvaBXAAAAgo"]
[Mon Jun 15 20:15:44.237692 2026] [security2:error] [pid 51003:tid 51197] [client 85.204.70.104:52612] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.hotelgrandpalacecbe.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ajCx0MpsKyvb75pkSvaBxAAAAc8"]
[Mon Jun 15 20:15:44.484438 2026] [security2:error] [pid 51003:tid 51229] [client 95.108.213.209:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCx0MpsKyvb75pkSvaBzgAAAe8"]
[Mon Jun 15 20:15:44.487593 2026] [security2:error] [pid 51003:tid 51224] [client 95.108.213.209:61758] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCx0MpsKyvb75pkSvaBygAB6mA"]
[Mon Jun 15 20:15:44.552131 2026] [security2:error] [pid 51003:tid 51151] [client 121.229.156.113:33956] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.symbolindia.com"] [uri "/time-line.html"] [unique_id "ajCx0MpsKyvb75pkSvaB0QAAAaE"]
[Mon Jun 15 20:15:44.552267 2026] [security2:error] [pid 51003:tid 51151] [client 121.229.156.113:33956] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.symbolindia.com"] [uri "/time-line.html"] [unique_id "ajCx0MpsKyvb75pkSvaB0QAAAaE"]
[Mon Jun 15 20:15:44.739137 2026] [security2:error] [pid 51003:tid 51157] [client 57.141.14.39:20632] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCx0MpsKyvb75pkSvaB1AABp3E"]
[Mon Jun 15 20:15:44.787272 2026] [security2:error] [pid 51003:tid 51198] [client 85.204.70.104:52626] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.hotelgrandpalacecbe.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ajCx0MpsKyvb75pkSvaB2gAAAdA"]
[Mon Jun 15 20:15:45.031922 2026] [security2:error] [pid 51003:tid 51173] [client 5.255.231.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCx0MpsKyvb75pkSvaB6AAAAbc"]
[Mon Jun 15 20:15:45.041076 2026] [security2:error] [pid 51003:tid 51203] [client 5.255.231.116:49678] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCx0MpsKyvb75pkSvaB5QAB1WI"]
[Mon Jun 15 20:15:45.335179 2026] [security2:error] [pid 51003:tid 51179] [client 85.204.70.104:52634] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.hotelgrandpalacecbe.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ajCx0cpsKyvb75pkSvaB9QAAAb0"]
[Mon Jun 15 20:15:45.575223 2026] [security2:error] [pid 51003:tid 51224] [client 213.180.203.101:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCx0cpsKyvb75pkSvaB_AAAAeo"]
[Mon Jun 15 20:15:45.583636 2026] [security2:error] [pid 51003:tid 51168] [client 213.180.203.101:36448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCx0cpsKyvb75pkSvaB-gABsk0"]
[Mon Jun 15 20:15:45.871352 2026] [security2:error] [pid 51003:tid 51217] [client 85.204.70.104:52648] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.hotelgrandpalacecbe.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "ajCx0cpsKyvb75pkSvaCBAAAAeM"]
[Mon Jun 15 20:15:46.113533 2026] [security2:error] [pid 51003:tid 51202] [client 5.255.231.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCx0spsKyvb75pkSvaCCwAAAdQ"]
[Mon Jun 15 20:15:46.132968 2026] [security2:error] [pid 51003:tid 51259] [client 5.255.231.194:63954] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCx0cpsKyvb75pkSvaCBwACDQI"]
[Mon Jun 15 20:15:46.331827 2026] [security2:error] [pid 51003:tid 51245] [client 57.141.14.82:61574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCx0spsKyvb75pkSvaCEgAB_yM"]
[Mon Jun 15 20:15:46.427999 2026] [security2:error] [pid 51003:tid 51222] [client 85.204.70.104:52652] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.hotelgrandpalacecbe.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ajCx0spsKyvb75pkSvaCHgAAAeg"]
[Mon Jun 15 20:15:46.471384 2026] [security2:error] [pid 51003:tid 51197] [client 57.141.14.56:25118] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fifthestate.agency"] [uri "/index.php"] [unique_id "ajCx0spsKyvb75pkSvaCDwABzz8"]
[Mon Jun 15 20:15:46.707788 2026] [security2:error] [pid 51003:tid 51146] [client 95.108.213.214:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCx0spsKyvb75pkSvaCKgAAAZw"]
[Mon Jun 15 20:15:46.714723 2026] [security2:error] [pid 51003:tid 51144] [client 95.108.213.214:54862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCx0spsKyvb75pkSvaCJgABmlg"]
[Mon Jun 15 20:15:46.883465 2026] [security2:error] [pid 51003:tid 51029] [remote 91.146.99.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.99.146.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gspproperties1.com"] [uri "/wp-login.php"] [unique_id "ajCx0spsKyvb75pkSvaCNQACBhk"]
[Mon Jun 15 20:15:46.910602 2026] [security2:error] [pid 51003:tid 51167] [client 83.175.179.180:39181] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.pacerecruit.com"] [uri "/index.php"] [unique_id "ajCx0cpsKyvb75pkSvaB_QAAAbE"]
[Mon Jun 15 20:15:46.999524 2026] [security2:error] [pid 51003:tid 51161] [client 31.219.209.201:58812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.209.219.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCx0spsKyvb75pkSvaCOgAAAas"]
[Mon Jun 15 20:15:46.999626 2026] [security2:error] [pid 51003:tid 51161] [client 31.219.209.201:58812] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCx0spsKyvb75pkSvaCOgAAAas"]
[Mon Jun 15 20:15:47.001340 2026] [security2:error] [pid 51003:tid 51210] [client 85.204.70.104:52654] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.hotelgrandpalacecbe.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "ajCx08psKyvb75pkSvaCOwAAAdw"]
[Mon Jun 15 20:15:47.426219 2026] [security2:error] [pid 51003:tid 51258] [client 95.108.213.237:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCx08psKyvb75pkSvaCSAAAAgw"]
[Mon Jun 15 20:15:47.447010 2026] [security2:error] [pid 51003:tid 51134] [client 95.108.213.237:50144] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCx08psKyvb75pkSvaCQgABkGU"]
[Mon Jun 15 20:15:47.465023 2026] [security2:error] [pid 51003:tid 51023] [remote 91.146.99.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.99.146.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gspproperties1.com"] [uri "/wp-login.php"] [unique_id "ajCx08psKyvb75pkSvaCSgAB5BM"], referer: https://gspproperties1.com/wp-login.php
[Mon Jun 15 20:15:47.529544 2026] [security2:error] [pid 51003:tid 51179] [client 85.204.70.104:52668] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.hotelgrandpalacecbe.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "ajCx08psKyvb75pkSvaCVQAAAb0"]
[Mon Jun 15 20:15:47.821334 2026] [security2:error] [pid 51003:tid 51138] [client 95.108.213.101:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCx08psKyvb75pkSvaCXwAAAZQ"]
[Mon Jun 15 20:15:47.823123 2026] [security2:error] [pid 51003:tid 51142] [client 95.108.213.101:38574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCx08psKyvb75pkSvaCWgABmA0"]
[Mon Jun 15 20:15:47.825941 2026] [security2:error] [pid 51003:tid 51246] [client 95.108.213.136:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCx08psKyvb75pkSvaCYgAAAgA"]
[Mon Jun 15 20:15:47.828896 2026] [security2:error] [pid 51003:tid 51260] [client 95.108.213.136:57034] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCx08psKyvb75pkSvaCXAACDjw"]
[Mon Jun 15 20:15:47.894105 2026] [security2:error] [pid 51003:tid 51232] [client 57.141.14.75:43138] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCx08psKyvb75pkSvaCYAAB8nw"]
[Mon Jun 15 20:15:48.056141 2026] [security2:error] [pid 51003:tid 51239] [client 85.204.70.104:52680] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.hotelgrandpalacecbe.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ajCx1MpsKyvb75pkSvaCbAAAAfk"]
[Mon Jun 15 20:15:48.558571 2026] [security2:error] [pid 51003:tid 51083] [remote 87.106.70.198:39386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.70.106.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nilayamdham.org"] [uri "/wp-login.php"] [unique_id "ajCx1MpsKyvb75pkSvaCiAAB4k8"]
[Mon Jun 15 20:15:48.590539 2026] [security2:error] [pid 51003:tid 51179] [client 85.204.70.104:52696] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.hotelgrandpalacecbe.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ajCx1MpsKyvb75pkSvaCpAAAAb0"]
[Mon Jun 15 20:15:48.806951 2026] [security2:error] [pid 51003:tid 51130] [remote 87.106.70.198:39386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.70.106.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nilayamdham.org"] [uri "/wp-login.php"] [unique_id "ajCx1MpsKyvb75pkSvaCqQACCX4"], referer: https://nilayamdham.org/wp-login.php
[Mon Jun 15 20:15:49.079123 2026] [security2:error] [pid 51003:tid 51184] [client 192.111.139.162:37783] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "madakasira.in"] [uri "/xmlrpc.php"] [unique_id "ajCx1MpsKyvb75pkSvaCqAAAAcI"], referer: https://madakasira.in/?do=%2Fblog%2F8090%2Fcritical-factors-for-online-games-a-background
[Mon Jun 15 20:15:49.152879 2026] [security2:error] [pid 51003:tid 51239] [client 85.204.70.104:52710] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.hotelgrandpalacecbe.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ajCx1cpsKyvb75pkSvaC1gAAAfk"]
[Mon Jun 15 20:15:49.220236 2026] [security2:error] [pid 51003:tid 51161] [client 151.243.252.163:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCx1MpsKyvb75pkSvaCpwABqzc"], referer: https://mywordsnthoughts.com/ammadi-ammadi-song-from-desingu-raja-lyrics-in-english-with-translation/
[Mon Jun 15 20:15:49.253268 2026] [security2:error] [pid 51003:tid 51047] [remote 151.243.252.163:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCx1MpsKyvb75pkSvaCqgABqis"], referer: https://mywordsnthoughts.com/ammadi-ammadi-song-from-desingu-raja-lyrics-in-english-with-translation/
[Mon Jun 15 20:15:49.350510 2026] [security2:error] [pid 51003:tid 51154] [client 65.111.7.242:55621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.7.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rajunandkardeputycollector.blog"] [uri "/wp-login.php"] [unique_id "ajCx1cpsKyvb75pkSvaC3gAAAaQ"], referer: https://rajunandkardeputycollector.blog/wp-login.php
[Mon Jun 15 20:15:49.452598 2026] [security2:error] [pid 51003:tid 51224] [client 57.141.14.64:62726] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCx1cpsKyvb75pkSvaC3wAB6iM"]
[Mon Jun 15 20:15:49.542720 2026] [security2:error] [pid 51003:tid 51251] [client 143.244.57.88:55752] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "rkfreshmart.net"] [uri "/wp-admin/user/index.php"] [unique_id "ajCx1cpsKyvb75pkSvaC1QAAAgU"]
[Mon Jun 15 20:15:49.695038 2026] [security2:error] [pid 51003:tid 51168] [client 85.204.70.104:52724] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.hotelgrandpalacecbe.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ajCx1cpsKyvb75pkSvaC9QAAAbI"]
[Mon Jun 15 20:15:49.706456 2026] [security2:error] [pid 51003:tid 51144] [client 20.169.78.123:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dountsmenu.onl"] [uri "/index.php"] [unique_id "ajCx1cpsKyvb75pkSvaC4AAAAZo"]
[Mon Jun 15 20:15:49.808747 2026] [security2:error] [pid 51003:tid 51227] [client 187.126.54.197:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kthemani.com"] [uri "/index.php"] [unique_id "ajCx08psKyvb75pkSvaCaAAB7Sg"]
[Mon Jun 15 20:15:49.941425 2026] [security2:error] [pid 51003:tid 51184] [client 143.244.57.88:55752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rkfreshmart.net"] [uri "/wp-login.php"] [unique_id "ajCx1cpsKyvb75pkSvaC_wAAAcI"]
[Mon Jun 15 20:15:49.941532 2026] [security2:error] [pid 51003:tid 51184] [client 143.244.57.88:55752] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rkfreshmart.net"] [uri "/wp-login.php"] [unique_id "ajCx1cpsKyvb75pkSvaC_wAAAcI"]
[Mon Jun 15 20:15:50.060487 2026] [security2:error] [pid 51003:tid 51178] [client 213.180.203.158:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCx1spsKyvb75pkSvaDBwAAAbw"]
[Mon Jun 15 20:15:50.063281 2026] [security2:error] [pid 51003:tid 51180] [client 213.180.203.158:37352] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCx1cpsKyvb75pkSvaDBAABvhk"]
[Mon Jun 15 20:15:50.124036 2026] [security2:error] [pid 51003:tid 51086] [remote 78.142.18.172:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.leapinfosys.com"] [uri "/wp-login.php"] [unique_id "ajCx1spsKyvb75pkSvaDDAAB5VI"]
[Mon Jun 15 20:15:50.229584 2026] [security2:error] [pid 51003:tid 51253] [client 34.90.69.83:32768] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "bridgegap.co.in"] [uri "/"] [unique_id "ajCx1spsKyvb75pkSvaDEgAAAgc"]
[Mon Jun 15 20:15:50.229684 2026] [security2:error] [pid 51003:tid 51253] [client 34.90.69.83:32768] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "bridgegap.co.in"] [uri "/"] [unique_id "ajCx1spsKyvb75pkSvaDEgAAAgc"]
[Mon Jun 15 20:15:50.229978 2026] [security2:error] [pid 51003:tid 51136] [client 85.204.70.104:52740] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.hotelgrandpalacecbe.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "ajCx1spsKyvb75pkSvaDFAAAAZI"]
[Mon Jun 15 20:15:50.281363 2026] [security2:error] [pid 51003:tid 51234] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "starterbitescorp.com"] [uri "/index.php"] [unique_id "ajCx1cpsKyvb75pkSvaC6QAAAfQ"]
[Mon Jun 15 20:15:50.702513 2026] [security2:error] [pid 51003:tid 51220] [client 2a03:2880:f806:3:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ruchini.hemani.finance"] [uri "/index.php"] [unique_id "ajCx1spsKyvb75pkSvaDGwAB5hc"]
[Mon Jun 15 20:15:50.754641 2026] [security2:error] [pid 51003:tid 51193] [client 85.204.70.104:52742] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.hotelgrandpalacecbe.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "ajCx1spsKyvb75pkSvaDJwAAAcs"]
[Mon Jun 15 20:15:50.768112 2026] [security2:error] [pid 51003:tid 51120] [remote 57.141.14.71:46808] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCx1spsKyvb75pkSvaDIQACA3Q"]
[Mon Jun 15 20:15:50.847341 2026] [security2:error] [pid 51003:tid 51139] [client 65.111.30.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.procrastinatingworker.imcorp.in"] [uri "/index.php"] [unique_id "ajCx1spsKyvb75pkSvaDJgAAAZU"]
[Mon Jun 15 20:15:50.973336 2026] [security2:error] [pid 51003:tid 51146] [client 157.55.39.6:63852] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ybsolutions.in"] [uri "/index.php"] [unique_id "ajCx1spsKyvb75pkSvaDNQABnHw"]
[Mon Jun 15 20:15:51.118961 2026] [security2:error] [pid 51003:tid 51194] [client 142.248.80.72:35340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kavadevelopers.kavadevelopers.com"] [uri "/.env"] [unique_id "ajCx18psKyvb75pkSvaDPQAAAcw"]
[Mon Jun 15 20:15:51.152926 2026] [http2:info] [pid 53359:tid 53359] h2_workers: created with min=128 max=192 idle_ms=600000
[Mon Jun 15 20:15:51.208692 2026] [security2:error] [pid 51003:tid 51146] [client 95.108.213.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCx18psKyvb75pkSvaDXgAAAZw"]
[Mon Jun 15 20:15:51.223034 2026] [security2:error] [pid 51003:tid 51220] [client 95.108.213.143:56398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCx18psKyvb75pkSvaDNwAB5jE"]
[Mon Jun 15 20:15:51.343421 2026] [security2:error] [pid 51003:tid 51121] [remote 47.128.119.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCx1spsKyvb75pkSvaDMAABy3U"]
[Mon Jun 15 20:15:51.390648 2026] [security2:error] [pid 51003:tid 51183] [client 85.204.70.104:52758] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.hotelgrandpalacecbe.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ajCx18psKyvb75pkSvaDagAAAcE"]
[Mon Jun 15 20:15:51.408460 2026] [security2:error] [pid 51003:tid 51201] [client 52.167.144.161:31400] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "societytodaynews.com"] [uri "/index.php"] [unique_id "ajCx18psKyvb75pkSvaDYAAB0wQ"]
[Mon Jun 15 20:15:51.694711 2026] [security2:error] [pid 51003:tid 51153] [client 142.248.80.72:35500] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kavadevelopers.kavadevelopers.com"] [uri "/server/.env"] [unique_id "ajCx18psKyvb75pkSvaDfAAAAaM"]
[Mon Jun 15 20:15:51.694750 2026] [security2:error] [pid 51003:tid 51171] [client 142.248.80.72:35460] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kavadevelopers.kavadevelopers.com"] [uri "/api/.env"] [unique_id "ajCx18psKyvb75pkSvaDdwAAAbU"]
[Mon Jun 15 20:15:51.694791 2026] [security2:error] [pid 51003:tid 51147] [client 142.248.80.72:35468] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kavadevelopers.kavadevelopers.com"] [uri "/backend/.env"] [unique_id "ajCx18psKyvb75pkSvaDewAAAZ0"]
[Mon Jun 15 20:15:51.695187 2026] [security2:error] [pid 51003:tid 51257] [client 142.248.80.72:35374] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.kavadevelopers.kavadevelopers.com"] [uri "/.env.backup"] [unique_id "ajCx18psKyvb75pkSvaDeAAAAgs"]
[Mon Jun 15 20:15:51.701834 2026] [security2:error] [pid 51003:tid 51012] [remote 78.142.18.172:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.leapinfosys.com"] [uri "/wp-login.php"] [unique_id "ajCx18psKyvb75pkSvaDdgACBwg"], referer: https://mail.leapinfosys.com/wp-login.php
[Mon Jun 15 20:15:51.705709 2026] [security2:error] [pid 51003:tid 51230] [client 142.248.80.72:35332] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.kavadevelopers.kavadevelopers.com"] [uri "/.env.bak"] [unique_id "ajCx18psKyvb75pkSvaDfQAAAfA"]
[Mon Jun 15 20:15:51.720854 2026] [security2:error] [pid 51003:tid 51227] [client 142.248.80.72:35492] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kavadevelopers.kavadevelopers.com"] [uri "/src/.env"] [unique_id "ajCx18psKyvb75pkSvaDggAAAe0"]
[Mon Jun 15 20:15:51.772563 2026] [core:error] [pid 53359:tid 53499] [client 40.77.167.101:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jun 15 20:15:51.772582 2026] [core:error] [pid 53359:tid 53499] [client 40.77.167.101:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jun 15 20:15:51.780382 2026] [security2:error] [pid 51003:tid 51188] [client 142.248.80.72:35518] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kavadevelopers.kavadevelopers.com"] [uri "/public/.env"] [unique_id "ajCx18psKyvb75pkSvaDjQAAAcY"]
[Mon Jun 15 20:15:51.793013 2026] [security2:error] [pid 51003:tid 51184] [client 142.248.80.72:35358] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kavadevelopers.kavadevelopers.com"] [uri "/laravel/.env"] [unique_id "ajCx18psKyvb75pkSvaDnwAAAcI"]
[Mon Jun 15 20:15:51.794769 2026] [security2:error] [pid 51003:tid 51141] [client 142.248.80.72:35386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kavadevelopers.kavadevelopers.com"] [uri "/app/.env"] [unique_id "ajCx18psKyvb75pkSvaDqAAAAZc"]
[Mon Jun 15 20:15:51.794783 2026] [security2:error] [pid 51003:tid 51165] [client 142.248.80.72:35444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kavadevelopers.kavadevelopers.com"] [uri "/web/.env"] [unique_id "ajCx18psKyvb75pkSvaDqwAAAa8"]
[Mon Jun 15 20:15:51.795249 2026] [security2:error] [pid 51003:tid 51231] [client 142.248.80.72:35420] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.kavadevelopers.kavadevelopers.com"] [uri "/.env.old"] [unique_id "ajCx18psKyvb75pkSvaDrAAAAfE"]
[Mon Jun 15 20:15:51.937318 2026] [security2:error] [pid 51003:tid 51234] [client 85.204.70.104:52772] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.hotelgrandpalacecbe.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ajCx18psKyvb75pkSvaDtAAAAfQ"]
[Mon Jun 15 20:15:52.057915 2026] [security2:error] [pid 51003:tid 51242] [client 192.140.64.94:29606] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCx2MpsKyvb75pkSvaDtwAAAfw"]
[Mon Jun 15 20:15:52.061277 2026] [security2:error] [pid 51003:tid 51242] [client 192.140.64.94:29606] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCx2MpsKyvb75pkSvaDtwAAAfw"]
[Mon Jun 15 20:15:52.206436 2026] [security2:error] [pid 51003:tid 51245] [client 57.141.14.60:58490] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCx2MpsKyvb75pkSvaDuQAB_1k"]
[Mon Jun 15 20:15:52.418146 2026] [security2:error] [pid 51003:tid 51040] [remote 74.7.227.178:48190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "softhubtechno.ehx.czu.mybluehostin.me"] [uri "/images/js/images/clients/Admin/logo/js/img/carrer.php"] [unique_id "ajCx2MpsKyvb75pkSvaDxwABuSQ"], referer: https://softhubtechno.ehx.czu.mybluehostin.me/images/js/images/clients/Admin/logo/js/img/b_drop.png
[Mon Jun 15 20:15:52.459108 2026] [security2:error] [pid 53359:tid 53510] [client 85.204.70.104:52778] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.hotelgrandpalacecbe.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "ajCx2PC2Xs1VMQlhsgacSwAAAiM"]
[Mon Jun 15 20:15:52.470584 2026] [security2:error] [pid 51003:tid 51221] [client 213.180.203.167:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCx2MpsKyvb75pkSvaDyAAAAec"]
[Mon Jun 15 20:15:52.473212 2026] [security2:error] [pid 51003:tid 51206] [client 213.180.203.167:56004] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCx2MpsKyvb75pkSvaDxgAB2Cc"]
[Mon Jun 15 20:15:52.588531 2026] [security2:error] [pid 53359:tid 53368] [remote 47.128.119.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCx2PC2Xs1VMQlhsgacSAACHwI"], referer: https://mywordsnthoughts.com/tag/krishna-shankar-premam/
[Mon Jun 15 20:15:52.591141 2026] [security2:error] [pid 51003:tid 51020] [remote 47.128.119.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCx2MpsKyvb75pkSvaDvAABtBA"], referer: https://mywordsnthoughts.com/tag/krishna-shankar-premam/
[Mon Jun 15 20:15:52.683264 2026] [security2:error] [pid 53359:tid 53509] [client 186.151.96.25:59608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "wantpg.com"] [uri "/public/index.php/pg-in-siah-chol-1254176.html"] [unique_id "ajCx2PC2Xs1VMQlhsgacTQAAAiI"]
[Mon Jun 15 20:15:52.887595 2026] [security2:error] [pid 53359:tid 53524] [client 47.79.201.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "brainstrom.org"] [uri "/index.php"] [unique_id "ajCx2PC2Xs1VMQlhsgacTwACMQM"], referer: https://www.google.com/
[Mon Jun 15 20:15:52.944810 2026] [security2:error] [pid 53359:tid 53371] [remote 110.249.202.148:28216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "steelsalesco.com"] [uri "/wp-content/uploads/2021/08/Sockolets.jpg"] [unique_id "ajCx2PC2Xs1VMQlhsgacVAACPAU"]
[Mon Jun 15 20:15:52.998950 2026] [security2:error] [pid 53359:tid 53536] [client 5.255.231.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCx2PC2Xs1VMQlhsgacVQAAAj0"]
[Mon Jun 15 20:15:53.002534 2026] [security2:error] [pid 53359:tid 53522] [client 5.255.231.33:59286] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCx2PC2Xs1VMQlhsgacUgACLwQ"]
[Mon Jun 15 20:15:53.023362 2026] [security2:error] [pid 51003:tid 51143] [client 47.128.117.155:23900] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "inspirethenation.in"] [uri "/robots.txt"] [unique_id "ajCx2cpsKyvb75pkSvaD2QAAAZk"]
[Mon Jun 15 20:15:53.283925 2026] [security2:error] [pid 51003:tid 51147] [client 142.248.80.72:36126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "www.kavadevelopers.kavadevelopers.com"] [uri "/.env.production.copy"] [unique_id "ajCx2cpsKyvb75pkSvaD4wAAAZ0"]
[Mon Jun 15 20:15:53.372940 2026] [security2:error] [pid 53359:tid 53552] [client 91.92.40.172:55102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.40.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pages.controlprint.co.in"] [uri "/wp-login.php"] [unique_id "ajCx2fC2Xs1VMQlhsgacWwAAAk0"]
[Mon Jun 15 20:15:53.516263 2026] [security2:error] [pid 51003:tid 51219] [client 95.108.213.213:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCx2cpsKyvb75pkSvaD6wAAAeU"]
[Mon Jun 15 20:15:53.563832 2026] [security2:error] [pid 51003:tid 51154] [client 95.108.213.213:44400] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCx2cpsKyvb75pkSvaD6gABpFY"]
[Mon Jun 15 20:15:54.073280 2026] [security2:error] [pid 51003:tid 51218] [client 213.180.203.137:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCx2spsKyvb75pkSvaD_QAAAeQ"]
[Mon Jun 15 20:15:54.077793 2026] [security2:error] [pid 53359:tid 53576] [client 213.180.203.137:55430] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCx2fC2Xs1VMQlhsgacaAACZQg"]
[Mon Jun 15 20:15:54.241993 2026] [security2:error] [pid 51003:tid 51163] [client 57.141.14.3:50058] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCx2spsKyvb75pkSvaEBAABrWA"]
[Mon Jun 15 20:15:54.516136 2026] [security2:error] [pid 51003:tid 51164] [client 142.248.80.72:36126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.kavadevelopers.kavadevelopers.com"] [uri "/.env~"] [unique_id "ajCx2spsKyvb75pkSvaEEQAAAa4"]
[Mon Jun 15 20:15:54.705660 2026] [security2:error] [pid 51003:tid 51219] [client 142.248.80.72:35752] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.kavadevelopers.kavadevelopers.com"] [uri "/.env.swp"] [unique_id "ajCx2spsKyvb75pkSvaEFAAAAeU"]
[Mon Jun 15 20:15:54.710240 2026] [security2:error] [pid 51003:tid 51224] [client 142.248.80.72:35826] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "www.kavadevelopers.kavadevelopers.com"] [uri "/.env.orig"] [unique_id "ajCx2spsKyvb75pkSvaEFQAAAeo"]
[Mon Jun 15 20:15:54.902868 2026] [security2:error] [pid 53359:tid 53600] [client 142.248.80.72:36994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "www.kavadevelopers.kavadevelopers.com"] [uri "/.env.copy"] [unique_id "ajCx2vC2Xs1VMQlhsgaccwAAAn0"]
[Mon Jun 15 20:15:54.912953 2026] [security2:error] [pid 51003:tid 51170] [client 142.248.80.72:35624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.kavadevelopers.kavadevelopers.com"] [uri "/.env.local.bak"] [unique_id "ajCx2spsKyvb75pkSvaEGwAAAbQ"]
[Mon Jun 15 20:15:55.005638 2026] [security2:error] [pid 51003:tid 51215] [client 142.248.80.72:36954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.kavadevelopers.kavadevelopers.com"] [uri "/.env.local.old"] [unique_id "ajCx28psKyvb75pkSvaEHAAAAeE"]
[Mon Jun 15 20:15:55.014190 2026] [security2:error] [pid 51003:tid 51168] [client 142.248.80.72:37114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.kavadevelopers.kavadevelopers.com"] [uri "/.env.production.old"] [unique_id "ajCx28psKyvb75pkSvaEHgAAAbI"]
[Mon Jun 15 20:15:55.014193 2026] [security2:error] [pid 51003:tid 51141] [client 142.248.80.72:37048] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "www.kavadevelopers.kavadevelopers.com"] [uri "/.env.local.copy"] [unique_id "ajCx28psKyvb75pkSvaEHQAAAZc"]
[Mon Jun 15 20:15:55.014197 2026] [security2:error] [pid 53359:tid 53596] [client 142.248.80.72:37034] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "www.kavadevelopers.kavadevelopers.com"] [uri "/.env.local.orig"] [unique_id "ajCx2_C2Xs1VMQlhsgacdgAAAnk"]
[Mon Jun 15 20:15:55.014199 2026] [security2:error] [pid 53359:tid 53597] [client 142.248.80.72:37026] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.kavadevelopers.kavadevelopers.com"] [uri "/.env.local.swp"] [unique_id "ajCx2_C2Xs1VMQlhsgacdQAAAno"]
[Mon Jun 15 20:15:55.014486 2026] [security2:error] [pid 51003:tid 51199] [client 142.248.80.72:36926] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.kavadevelopers.kavadevelopers.com"] [uri "/.env.production~"] [unique_id "ajCx28psKyvb75pkSvaEHwAAAdE"]
[Mon Jun 15 20:15:55.014499 2026] [security2:error] [pid 53359:tid 53591] [client 142.248.80.72:37112] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "www.kavadevelopers.kavadevelopers.com"] [uri "/.env.production.orig"] [unique_id "ajCx2_C2Xs1VMQlhsgaceAAAAnQ"]
[Mon Jun 15 20:15:55.014647 2026] [security2:error] [pid 53359:tid 53589] [client 142.248.80.72:36938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.kavadevelopers.kavadevelopers.com"] [uri "/.env.production.swp"] [unique_id "ajCx2_C2Xs1VMQlhsgacdwAAAnI"]
[Mon Jun 15 20:15:55.015163 2026] [security2:error] [pid 53359:tid 53592] [client 142.248.80.72:37058] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.kavadevelopers.kavadevelopers.com"] [uri "/.env.production.bak"] [unique_id "ajCx2_C2Xs1VMQlhsgaceQAAAnU"]
[Mon Jun 15 20:15:55.015173 2026] [security2:error] [pid 53359:tid 53594] [client 142.248.80.72:37002] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.kavadevelopers.kavadevelopers.com"] [uri "/.env.local.backup"] [unique_id "ajCx2_C2Xs1VMQlhsgacegAAAnc"]
[Mon Jun 15 20:15:55.015364 2026] [security2:error] [pid 53359:tid 53593] [client 142.248.80.72:37014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.kavadevelopers.kavadevelopers.com"] [uri "/.env.local~"] [unique_id "ajCx2_C2Xs1VMQlhsgacfAAAAnY"]
[Mon Jun 15 20:15:55.015448 2026] [security2:error] [pid 53359:tid 53590] [client 142.248.80.72:37066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.kavadevelopers.kavadevelopers.com"] [uri "/.env.production.backup"] [unique_id "ajCx2_C2Xs1VMQlhsgacfQAAAnM"]
[Mon Jun 15 20:15:55.128441 2026] [security2:error] [pid 53359:tid 53499] [client 95.108.213.179:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCx2_C2Xs1VMQlhsgacgAAAAhg"]
[Mon Jun 15 20:15:55.131498 2026] [security2:error] [pid 51003:tid 51220] [client 95.108.213.179:44126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCx28psKyvb75pkSvaEIQAB5mI"]
[Mon Jun 15 20:15:55.152850 2026] [security2:error] [pid 51003:tid 51024] [remote 57.141.14.73:64496] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCx28psKyvb75pkSvaEIwAB_RQ"]
[Mon Jun 15 20:15:55.265862 2026] [security2:error] [pid 51003:tid 51160] [client 37.66.23.126:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pehelfoundation.org"] [uri "/index.php"] [unique_id "ajCx2spsKyvb75pkSvaEAwAAAao"]
[Mon Jun 15 20:15:55.504561 2026] [security2:error] [pid 53359:tid 53520] [client 2a03:2880:f806:22:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ruchini.hemani.finance"] [uri "/index.php"] [unique_id "ajCx2_C2Xs1VMQlhsgachAACLQw"]
[Mon Jun 15 20:15:55.614238 2026] [security2:error] [pid 51003:tid 51207] [client 213.180.203.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCx28psKyvb75pkSvaEMAAAAdk"]
[Mon Jun 15 20:15:55.615382 2026] [security2:error] [pid 53359:tid 53510] [client 213.180.203.120:44572] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCx2_C2Xs1VMQlhsgachgACIw0"]
[Mon Jun 15 20:15:56.265486 2026] [security2:error] [pid 53359:tid 53548] [client 213.180.203.126:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCx3PC2Xs1VMQlhsgaclAAAAkk"]
[Mon Jun 15 20:15:56.268517 2026] [security2:error] [pid 53359:tid 53536] [client 213.180.203.126:41356] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCx3PC2Xs1VMQlhsgackQACPRQ"]
[Mon Jun 15 20:15:56.667367 2026] [security2:error] [pid 51003:tid 51184] [client 5.255.231.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCx3MpsKyvb75pkSvaERQAAAcI"]
[Mon Jun 15 20:15:56.669541 2026] [security2:error] [pid 51003:tid 51220] [client 5.255.231.203:36612] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCx3MpsKyvb75pkSvaEQwAB5gE"]
[Mon Jun 15 20:15:56.891241 2026] [security2:error] [pid 51003:tid 51196] [client 57.141.14.95:26353] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCx3MpsKyvb75pkSvaESQABzj8"]
[Mon Jun 15 20:15:57.033907 2026] [rewrite:error] [pid 53359:tid 53575] [client 47.79.199.108:13250] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:15:57.372012 2026] [security2:error] [pid 51003:tid 51253] [client 87.250.224.128:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCx3cpsKyvb75pkSvaEXAAAAgc"]
[Mon Jun 15 20:15:57.375886 2026] [security2:error] [pid 51003:tid 51207] [client 87.250.224.128:46234] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCx3cpsKyvb75pkSvaEWgAB2Uk"]
[Mon Jun 15 20:15:57.478961 2026] [security2:error] [pid 53359:tid 53609] [client 31.219.209.201:59423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.209.219.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCx3fC2Xs1VMQlhsgacsQAAAoY"]
[Mon Jun 15 20:15:57.479084 2026] [security2:error] [pid 53359:tid 53609] [client 31.219.209.201:59423] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCx3fC2Xs1VMQlhsgacsQAAAoY"]
[Mon Jun 15 20:15:57.494414 2026] [rewrite:error] [pid 53359:tid 53595] [client 47.79.199.108:13250] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:15:57.855299 2026] [security2:error] [pid 53359:tid 53505] [client 87.250.224.117:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCx3fC2Xs1VMQlhsgacugAAAh4"]
[Mon Jun 15 20:15:57.858661 2026] [security2:error] [pid 51003:tid 51143] [client 87.250.224.117:40838] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCx3cpsKyvb75pkSvaEYgABmW8"]
[Mon Jun 15 20:15:57.900049 2026] [security2:error] [pid 53359:tid 53497] [client 57.141.14.3:38318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCx3fC2Xs1VMQlhsgacuAACFho"]
[Mon Jun 15 20:15:57.921416 2026] [security2:error] [pid 53359:tid 53393] [remote 74.7.227.161:39832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.shreeramsweets.co.in"] [uri "/plugins/lightgallery/js/plugins/lightgallery/js/images_scroller/images/blog/grid/images_scroller/plugins/owl-carousel/css/images/images/background/hampers-gift.php"] [unique_id "ajCx3fC2Xs1VMQlhsgacvgACFRs"], referer: https://www.shreeramsweets.co.in/plugins/lightgallery/js/plugins/lightgallery/js/images_scroller/images/blog/grid/images_scroller/plugins/owl-carousel/css/images/images/background/bg1.jpg
[Mon Jun 15 20:15:58.072960 2026] [security2:error] [pid 51003:tid 51054] [remote 194.163.139.224:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.139.163.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "niftystags.com"] [uri "/wp-login.php"] [unique_id "ajCx3spsKyvb75pkSvaEcQAB1zI"]
[Mon Jun 15 20:15:58.321294 2026] [rewrite:error] [pid 51003:tid 51112] [remote 47.79.198.200:50240] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:15:58.425107 2026] [security2:error] [pid 51003:tid 51229] [client 213.180.203.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCx3spsKyvb75pkSvaEegAAAe8"]
[Mon Jun 15 20:15:58.426902 2026] [security2:error] [pid 51003:tid 51233] [client 213.180.203.151:64638] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCx3spsKyvb75pkSvaEdgAB83Q"]
[Mon Jun 15 20:15:58.573445 2026] [rewrite:error] [pid 51003:tid 51075] [remote 47.79.198.200:50240] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:15:58.646469 2026] [security2:error] [pid 53359:tid 53395] [remote 209.42.18.223:37226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shaalestate.com"] [uri "/wp-login.php"] [unique_id "ajCx3vC2Xs1VMQlhsgacxQACMx0"]
[Mon Jun 15 20:15:58.702443 2026] [security2:error] [pid 51003:tid 51064] [remote 194.163.139.224:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.139.163.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "niftystags.com"] [uri "/wp-login.php"] [unique_id "ajCx3spsKyvb75pkSvaEgQABnzw"], referer: https://niftystags.com/wp-login.php
[Mon Jun 15 20:15:58.911284 2026] [security2:error] [pid 53359:tid 53543] [client 104.207.39.116:38285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.39.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rajunandkardeputycollector.blog"] [uri "/wp-login.php"] [unique_id "ajCx3vC2Xs1VMQlhsgaczQAAAkQ"], referer: https://rajunandkardeputycollector.blog/wp-login.php
[Mon Jun 15 20:15:59.000092 2026] [security2:error] [pid 53359:tid 53563] [client 87.250.224.236:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCx3vC2Xs1VMQlhsgac0AAAAlg"]
[Mon Jun 15 20:15:59.016860 2026] [security2:error] [pid 53359:tid 53540] [client 87.250.224.236:63944] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCx3vC2Xs1VMQlhsgaczgACQSA"]
[Mon Jun 15 20:15:59.151169 2026] [security2:error] [pid 53359:tid 53399] [remote 57.141.14.89:39428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCx3_C2Xs1VMQlhsgac0QACYCE"]
[Mon Jun 15 20:15:59.440999 2026] [security2:error] [pid 53359:tid 53403] [remote 78.46.92.235:44334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.92.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "varunrastogi.com"] [uri "/wp-login.php"] [unique_id "ajCx3_C2Xs1VMQlhsgac1wACaSU"]
[Mon Jun 15 20:15:59.665783 2026] [security2:error] [pid 53359:tid 53404] [remote 78.46.92.235:44334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.92.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "varunrastogi.com"] [uri "/wp-login.php"] [unique_id "ajCx3_C2Xs1VMQlhsgac3AACZCY"], referer: https://varunrastogi.com/wp-login.php
[Mon Jun 15 20:15:59.750990 2026] [security2:error] [pid 51003:tid 51140] [client 207.46.13.126:8621] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "madanavonz.com"] [uri "/index.php"] [unique_id "ajCx38psKyvb75pkSvaEkAABlnU"]
[Mon Jun 15 20:15:59.974896 2026] [security2:error] [pid 53359:tid 53585] [client 57.141.14.12:55892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fifthestate.agency"] [uri "/index.php"] [unique_id "ajCx3_C2Xs1VMQlhsgac3gACbic"]
[Mon Jun 15 20:16:00.176103 2026] [security2:error] [pid 51003:tid 51088] [remote 64.131.86.2:54848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.86.131.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ruchiramaniar.com"] [uri "/wp-login.php"] [unique_id "ajCx4MpsKyvb75pkSvaEqQAB_VQ"]
[Mon Jun 15 20:16:00.242914 2026] [security2:error] [pid 51003:tid 51159] [client 5.255.231.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCx4MpsKyvb75pkSvaEqwAAAak"]
[Mon Jun 15 20:16:00.243931 2026] [security2:error] [pid 51003:tid 51215] [client 57.141.14.100:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pizzaa-menu.com"] [uri "/index.php"] [unique_id "ajCx38psKyvb75pkSvaEngAAAeE"]
[Mon Jun 15 20:16:00.254961 2026] [security2:error] [pid 51003:tid 51176] [client 5.255.231.40:39302] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCx38psKyvb75pkSvaEogABujA"]
[Mon Jun 15 20:16:00.337304 2026] [security2:error] [pid 51003:tid 51093] [remote 64.131.86.2:54848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.86.131.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ruchiramaniar.com"] [uri "/wp-login.php"] [unique_id "ajCx4MpsKyvb75pkSvaEsAABwFk"], referer: https://ruchiramaniar.com/wp-login.php
[Mon Jun 15 20:16:00.415452 2026] [rewrite:error] [pid 51003:tid 51082] [remote 47.79.197.2:3766] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:16:00.529302 2026] [security2:error] [pid 53359:tid 53513] [client 143.244.57.120:37648] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.surveylaya.com"] [uri "/wp-content/"] [unique_id "ajCx4PC2Xs1VMQlhsgac7wAAAiY"]
[Mon Jun 15 20:16:00.633789 2026] [security2:error] [pid 53359:tid 53503] [client 47.79.206.131:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "brainstrom.org"] [uri "/index.php"] [unique_id "ajCx4PC2Xs1VMQlhsgac7AACHC0"], referer: https://www.google.com/
[Mon Jun 15 20:16:00.674183 2026] [rewrite:error] [pid 51003:tid 51042] [remote 47.79.197.2:3766] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:16:00.695261 2026] [security2:error] [pid 51003:tid 51085] [remote 66.249.70.160:0] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.smgl.org"] [uri "/robots.txt"] [unique_id "ajCx4MpsKyvb75pkSvaEvgACC1E"]
[Mon Jun 15 20:16:00.728914 2026] [security2:error] [pid 53359:tid 53508] [client 136.144.43.157:31641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.43.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weedtale.com"] [uri "/wp-login.php"] [unique_id "ajCx4PC2Xs1VMQlhsgac8QAAAiE"]
[Mon Jun 15 20:16:00.837003 2026] [security2:error] [pid 51003:tid 51224] [client 136.144.43.174:57877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.43.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weedtale.com"] [uri "/wp-login.php"] [unique_id "ajCx4MpsKyvb75pkSvaExQAAAeo"]
[Mon Jun 15 20:16:01.037082 2026] [security2:error] [pid 51003:tid 51259] [client 57.141.14.105:58444] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCx4MpsKyvb75pkSvaEzQACDV0"]
[Mon Jun 15 20:16:01.374862 2026] [security2:error] [pid 53359:tid 53558] [client 5.255.231.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCx4fC2Xs1VMQlhsgac_QAAAlM"]
[Mon Jun 15 20:16:01.377707 2026] [security2:error] [pid 53359:tid 53529] [client 5.255.231.42:38136] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCx4fC2Xs1VMQlhsgac-wACNjE"]
[Mon Jun 15 20:16:01.378645 2026] [security2:error] [pid 51003:tid 51141] [client 54.197.11.88:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCx4cpsKyvb75pkSvaE0QABlw4"]
[Mon Jun 15 20:16:01.657693 2026] [security2:error] [pid 51003:tid 51249] [client 136.144.43.160:47529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.43.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weedtale.com"] [uri "/wp-login.php"] [unique_id "ajCx4cpsKyvb75pkSvaE3QAAAgM"]
[Mon Jun 15 20:16:01.809159 2026] [security2:error] [pid 53359:tid 53417] [remote 91.146.102.43:39370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.102.146.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cherubicindia.com"] [uri "/wp-login.php"] [unique_id "ajCx4fC2Xs1VMQlhsgadBAACQTM"]
[Mon Jun 15 20:16:01.917070 2026] [security2:error] [pid 51003:tid 51130] [remote 103.173.66.99:10488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.66.173.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "manomayasparkles.com"] [uri "/wp-login.php"] [unique_id "ajCx4cpsKyvb75pkSvaE5AABoX4"]
[Mon Jun 15 20:16:01.935309 2026] [security2:error] [pid 53359:tid 53590] [client 181.233.26.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kthemani.com"] [uri "/index.php"] [unique_id "ajCx3_C2Xs1VMQlhsgac4wAAAnM"]
[Mon Jun 15 20:16:02.106242 2026] [security2:error] [pid 53359:tid 53420] [remote 91.146.102.43:39370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.102.146.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cherubicindia.com"] [uri "/wp-login.php"] [unique_id "ajCx4vC2Xs1VMQlhsgadBwACiDY"], referer: https://cherubicindia.com/wp-login.php
[Mon Jun 15 20:16:02.417920 2026] [security2:error] [pid 51003:tid 51103] [remote 2a03:2880:f806:39:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ruchini.hemani.finance"] [uri "/index.php"] [unique_id "ajCx4spsKyvb75pkSvaE7wAB02M"]
[Mon Jun 15 20:16:02.453174 2026] [security2:error] [pid 53359:tid 53582] [client 192.140.64.94:29763] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCx4vC2Xs1VMQlhsgadEQAAAms"]
[Mon Jun 15 20:16:02.453300 2026] [security2:error] [pid 53359:tid 53582] [client 192.140.64.94:29763] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCx4vC2Xs1VMQlhsgadEQAAAms"]
[Mon Jun 15 20:16:02.488662 2026] [security2:error] [pid 51003:tid 51025] [remote 103.173.66.99:10488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.66.173.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "manomayasparkles.com"] [uri "/wp-login.php"] [unique_id "ajCx4spsKyvb75pkSvaE8QACBxU"], referer: https://manomayasparkles.com/wp-login.php
[Mon Jun 15 20:16:02.525670 2026] [security2:error] [pid 51003:tid 51036] [remote 57.141.14.73:62020] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCx4spsKyvb75pkSvaE8AABnyA"]
[Mon Jun 15 20:16:02.586593 2026] [rewrite:error] [pid 53359:tid 53425] [remote 47.79.199.59:19740] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:16:02.638407 2026] [security2:error] [pid 51003:tid 51016] [remote 54.39.203.55:44370] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.steelsalesco.com"] [uri "/stainless-steel-321-321h-fasteners-supplier-manufacturer/"] [unique_id "ajCx4spsKyvb75pkSvaE9AABuQw"]
[Mon Jun 15 20:16:02.638559 2026] [security2:error] [pid 51003:tid 51175] [client 54.39.203.55:44370] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.steelsalesco.com"] [uri "/stainless-steel-321-321h-fasteners-supplier-manufacturer/"] [unique_id "ajCx4spsKyvb75pkSvaE9AABuQw"]
[Mon Jun 15 20:16:02.762805 2026] [security2:error] [pid 51003:tid 51111] [remote 57.141.14.73:62024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.14.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wilsonoverseas.com"] [uri "/items/G437035876"] [unique_id "ajCx4spsKyvb75pkSvaE9gAB6Ws"]
[Mon Jun 15 20:16:02.799138 2026] [security2:error] [pid 51003:tid 51019] [remote 184.107.244.93:40700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.244.107.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "analyticsias.com"] [uri "/wp-login.php"] [unique_id "ajCx4spsKyvb75pkSvaE-AAB-A8"]
[Mon Jun 15 20:16:02.865854 2026] [rewrite:error] [pid 53359:tid 53427] [remote 47.79.199.59:19740] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:16:02.901742 2026] [security2:error] [pid 53359:tid 53428] [remote 40.77.167.51:60182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "everyads.in"] [uri "/public/----/2715jdhoqj.php"] [unique_id "ajCx4vC2Xs1VMQlhsgadGgACLj4"]
[Mon Jun 15 20:16:03.255293 2026] [security2:error] [pid 51003:tid 51021] [remote 184.107.244.93:40700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.244.107.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "analyticsias.com"] [uri "/wp-login.php"] [unique_id "ajCx48psKyvb75pkSvaFAAACBBE"], referer: https://analyticsias.com/wp-login.php
[Mon Jun 15 20:16:03.264928 2026] [security2:error] [pid 51003:tid 51117] [remote 103.127.30.137:59236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.30.127.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mizukicnc.com"] [uri "/wp-login.php"] [unique_id "ajCx48psKyvb75pkSvaE_wABknE"]
[Mon Jun 15 20:16:03.690300 2026] [security2:error] [pid 53359:tid 53570] [client 83.61.67.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kthemani.com"] [uri "/index.php"] [unique_id "ajCx4fC2Xs1VMQlhsgadBQACXzQ"]
[Mon Jun 15 20:16:03.733901 2026] [security2:error] [pid 51003:tid 51051] [remote 103.127.30.137:59236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.30.127.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mizukicnc.com"] [uri "/wp-login.php"] [unique_id "ajCx48psKyvb75pkSvaFCwABui8"], referer: https://mizukicnc.com/wp-login.php
[Mon Jun 15 20:16:04.044684 2026] [security2:error] [pid 51003:tid 51239] [client 57.141.14.60:30202] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCx48psKyvb75pkSvaFEwAB-R4"]
[Mon Jun 15 20:16:04.131795 2026] [security2:error] [pid 51003:tid 51089] [remote 74.7.243.250:54642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rentswale.ehx.czu.mybluehostin.me"] [uri "/css/admin/uploads/icon/admin/uploads/item/js/images/company_ifo.php"] [unique_id "ajCx5MpsKyvb75pkSvaFFwAByFU"], referer: https://rentswale.ehx.czu.mybluehostin.me/css/admin/uploads/icon/admin/uploads/item/js/images/ios.svg
[Mon Jun 15 20:16:04.480415 2026] [security2:error] [pid 53359:tid 53571] [client 65.111.30.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.procrastinatingworker.imcorp.in"] [uri "/index.php"] [unique_id "ajCx5PC2Xs1VMQlhsgadKwAAAmA"]
[Mon Jun 15 20:16:05.012613 2026] [security2:error] [pid 51003:tid 51192] [client 143.244.57.88:53682] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "rkfreshmart.net"] [uri "/wp-content/"] [unique_id "ajCx5cpsKyvb75pkSvaFKgAAAco"]
[Mon Jun 15 20:16:05.078141 2026] [security2:error] [pid 53359:tid 53611] [client 157.55.39.13:14634] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.mahavirgems.in"] [uri "/index.php"] [unique_id "ajCx5PC2Xs1VMQlhsgadLwACiEI"]
[Mon Jun 15 20:16:05.298416 2026] [security2:error] [pid 53359:tid 53435] [remote 176.61.149.165:59078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.149.61.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "smartchoicereviews.com"] [uri "/wp-login.php"] [unique_id "ajCx5fC2Xs1VMQlhsgadNgACdUU"]
[Mon Jun 15 20:16:05.315146 2026] [security2:error] [pid 53359:tid 53617] [client 57.141.14.79:21200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fifthestate.agency"] [uri "/index.php"] [unique_id "ajCx5fC2Xs1VMQlhsgadNAACjkM"]
[Mon Jun 15 20:16:05.434182 2026] [security2:error] [pid 53359:tid 53436] [remote 66.249.89.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ruchini.hemani.finance"] [uri "/index.php"] [unique_id "ajCx5fC2Xs1VMQlhsgadOAACWkY"]
[Mon Jun 15 20:16:05.534278 2026] [security2:error] [pid 53359:tid 53440] [remote 176.61.149.165:59078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.149.61.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "smartchoicereviews.com"] [uri "/wp-login.php"] [unique_id "ajCx5fC2Xs1VMQlhsgadQwACHUo"], referer: https://smartchoicereviews.com/wp-login.php
[Mon Jun 15 20:16:05.561150 2026] [security2:error] [pid 53359:tid 53502] [client 57.141.14.101:20096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCx5fC2Xs1VMQlhsgadPwACG0g"]
[Mon Jun 15 20:16:05.869376 2026] [rewrite:error] [pid 53359:tid 53591] [client 47.79.197.40:61964] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:16:06.115061 2026] [security2:error] [pid 51003:tid 51077] [remote 119.195.102.159:48172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.102.195.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blackhorsespac.com"] [uri "/wp-login.php"] [unique_id "ajCx5spsKyvb75pkSvaFPgACBEk"]
[Mon Jun 15 20:16:06.331862 2026] [rewrite:error] [pid 53359:tid 53534] [client 47.79.197.40:61964] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:16:06.570712 2026] [security2:error] [pid 51003:tid 51099] [remote 119.195.102.159:48172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.102.195.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blackhorsespac.com"] [uri "/wp-login.php"] [unique_id "ajCx5spsKyvb75pkSvaFSgABtF8"], referer: https://blackhorsespac.com/wp-login.php
[Mon Jun 15 20:16:06.978250 2026] [security2:error] [pid 51003:tid 51146] [client 57.141.14.19:63592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCx5spsKyvb75pkSvaFUgABnHI"]
[Mon Jun 15 20:16:07.069273 2026] [security2:error] [pid 51003:tid 51063] [remote 185.110.189.235:39750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.189.110.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "performyoga.com"] [uri "/wp-login.php"] [unique_id "ajCx58psKyvb75pkSvaFVAAB7Ds"]
[Mon Jun 15 20:16:07.137161 2026] [security2:error] [pid 51003:tid 51171] [client 65.111.30.222:11069] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.procrastinatingworker.imcorp.in"] [uri "/.env"] [unique_id "ajCx58psKyvb75pkSvaFWAAAAbU"]
[Mon Jun 15 20:16:07.137573 2026] [rewrite:error] [pid 51003:tid 51128] [remote 47.79.199.83:7038] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:16:07.146845 2026] [security2:error] [pid 53359:tid 53455] [remote 223.178.214.44:44386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.214.178.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "speakingthoughts.in"] [uri "/wp-login.php"] [unique_id "ajCx5_C2Xs1VMQlhsgadZQACc1k"]
[Mon Jun 15 20:16:07.292428 2026] [security2:error] [pid 53359:tid 53612] [client 57.141.14.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hemani.finance"] [uri "/index.php"] [unique_id "ajCx5_C2Xs1VMQlhsgadYwAAAok"]
[Mon Jun 15 20:16:07.385454 2026] [rewrite:error] [pid 51003:tid 51009] [remote 47.79.199.83:7038] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:16:07.620289 2026] [security2:error] [pid 53359:tid 53579] [client 186.14.223.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kthemani.com"] [uri "/index.php"] [unique_id "ajCx5fC2Xs1VMQlhsgadSwAAAmg"]
[Mon Jun 15 20:16:07.910388 2026] [security2:error] [pid 51003:tid 51254] [client 52.167.144.172:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "everyads.in"] [uri "/public/index.php"] [unique_id "ajCx58psKyvb75pkSvaFbQAAAgg"]
[Mon Jun 15 20:16:08.019699 2026] [security2:error] [pid 51003:tid 51119] [remote 185.110.189.235:39750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.189.110.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "performyoga.com"] [uri "/wp-login.php"] [unique_id "ajCx6MpsKyvb75pkSvaFdAACA3M"], referer: https://performyoga.com/wp-login.php
[Mon Jun 15 20:16:08.031783 2026] [security2:error] [pid 51003:tid 51158] [client 31.219.209.201:60034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.209.219.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCx6MpsKyvb75pkSvaFdQAAAag"]
[Mon Jun 15 20:16:08.031863 2026] [security2:error] [pid 51003:tid 51158] [client 31.219.209.201:60034] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCx6MpsKyvb75pkSvaFdQAAAag"]
[Mon Jun 15 20:16:08.620819 2026] [security2:error] [pid 51003:tid 51168] [client 57.141.14.96:47031] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCx6MpsKyvb75pkSvaFfQABsnc"]
[Mon Jun 15 20:16:09.052104 2026] [security2:error] [pid 53359:tid 53538] [client 47.79.207.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "societytodaynews.com"] [uri "/index.php"] [unique_id "ajCx6PC2Xs1VMQlhsgadmgAAAj8"], referer: https://www.google.com/
[Mon Jun 15 20:16:09.261369 2026] [rewrite:error] [pid 51003:tid 51042] [remote 47.79.199.11:39512] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:16:09.435942 2026] [security2:error] [pid 51003:tid 51197] [client 57.141.14.88:36922] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "majividyarthikes.com"] [uri "/index.php"] [unique_id "ajCx6cpsKyvb75pkSvaFkwABzz0"]
[Mon Jun 15 20:16:09.535685 2026] [rewrite:error] [pid 51003:tid 51097] [remote 47.79.199.11:39512] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:16:09.588020 2026] [security2:error] [pid 53359:tid 53492] [remote 162.254.36.150:58452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.36.254.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nrmejournals.com"] [uri "/wp-login.php"] [unique_id "ajCx6fC2Xs1VMQlhsgadswACiX4"]
[Mon Jun 15 20:16:09.713815 2026] [lsapi:error] [pid 51003:tid 51012] [remote 77.101.45.6:0] [host www.kthemani.com] Error on sending request(GET /en/products/25640615/ HTTP/2.0); uri(/index.php) content-length(0): ReceiveAckHdr: nothing to read from backend (LVE ID 1402; user ID 1402), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html
[Mon Jun 15 20:16:09.797423 2026] [security2:error] [pid 53359:tid 53368] [remote 162.254.36.150:58452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.36.254.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nrmejournals.com"] [uri "/wp-login.php"] [unique_id "ajCx6fC2Xs1VMQlhsgaduAACLgI"], referer: https://nrmejournals.com/wp-login.php
[Mon Jun 15 20:16:09.911598 2026] [security2:error] [pid 53359:tid 53490] [remote 40.77.167.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCx6fC2Xs1VMQlhsgadrAACiHw"]
[Mon Jun 15 20:16:09.927338 2026] [security2:error] [pid 53359:tid 53369] [remote 74.7.242.32:55866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.242.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "my-eyezzy.webiknows.net"] [uri "/vendor/magnific-popup/vendor/magnific-popup/images/main-banner/images/testimonials/css/images/vendor/magnific-popup/swiper/js/doctor/index.php"] [unique_id "ajCx6fC2Xs1VMQlhsgaduwACYQM"], referer: https://my-eyezzy.webiknows.net/vendor/magnific-popup/vendor/magnific-popup/images/main-banner/images/testimonials/css/images/vendor/magnific-popup/swiper/js/jquery.min.js
[Mon Jun 15 20:16:10.166262 2026] [security2:error] [pid 51003:tid 51031] [remote 176.61.149.165:59094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.149.61.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srivyjayanthi.com"] [uri "/wp-login.php"] [unique_id "ajCx6spsKyvb75pkSvaFrQABsRs"]
[Mon Jun 15 20:16:10.171934 2026] [security2:error] [pid 53359:tid 53373] [remote 57.141.14.73:57802] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCx6vC2Xs1VMQlhsgadvgACMgc"]
[Mon Jun 15 20:16:10.420802 2026] [security2:error] [pid 53359:tid 53377] [remote 57.141.14.2:63405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.14.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wilsonoverseas.com"] [uri "/items/G437035876"] [unique_id "ajCx6vC2Xs1VMQlhsgadygAChgs"]
[Mon Jun 15 20:16:10.440035 2026] [security2:error] [pid 53359:tid 53378] [remote 78.46.92.235:54764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.92.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "divonik.com"] [uri "/wp-login.php"] [unique_id "ajCx6vC2Xs1VMQlhsgadywACIQw"]
[Mon Jun 15 20:16:10.440099 2026] [security2:error] [pid 51003:tid 51130] [remote 176.61.149.165:59094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.149.61.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srivyjayanthi.com"] [uri "/wp-login.php"] [unique_id "ajCx6spsKyvb75pkSvaFsQAByH4"], referer: https://srivyjayanthi.com/wp-login.php
[Mon Jun 15 20:16:10.641553 2026] [security2:error] [pid 53359:tid 53384] [remote 78.46.92.235:54764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.92.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "divonik.com"] [uri "/wp-login.php"] [unique_id "ajCx6vC2Xs1VMQlhsgad0AACSRI"], referer: https://divonik.com/wp-login.php
[Mon Jun 15 20:16:10.793202 2026] [security2:error] [pid 51003:tid 51194] [client 57.141.14.51:62852] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rohandasgupta.com"] [uri "/index.php"] [unique_id "ajCx6spsKyvb75pkSvaFtgABzBw"]
[Mon Jun 15 20:16:10.922908 2026] [security2:error] [pid 53359:tid 53383] [remote 57.141.14.64:22888] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCx6vC2Xs1VMQlhsgad0wACPhE"]
[Mon Jun 15 20:16:11.176862 2026] [security2:error] [pid 51003:tid 51189] [client 5.8.35.241:19004] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "tampapowerwashers.com"] [uri "/wp-login.php"] [unique_id "ajCx6cpsKyvb75pkSvaFmwAAAcc"]
[Mon Jun 15 20:16:11.179367 2026] [security2:error] [pid 53359:tid 53569] [client 57.141.14.101:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hemani.finance"] [uri "/index.php"] [unique_id "ajCx6vC2Xs1VMQlhsgad1AAAAl4"]
[Mon Jun 15 20:16:11.239530 2026] [security2:error] [pid 51003:tid 51134] [client 35.204.200.243:49152] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.nutreefarm.com"] [uri "/"] [unique_id "ajCx68psKyvb75pkSvaFyQAAAZA"]
[Mon Jun 15 20:16:11.239642 2026] [security2:error] [pid 51003:tid 51134] [client 35.204.200.243:49152] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mail.nutreefarm.com"] [uri "/"] [unique_id "ajCx68psKyvb75pkSvaFyQAAAZA"]
[Mon Jun 15 20:16:11.253383 2026] [security2:error] [pid 53359:tid 53522] [client 47.79.206.198:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "designhub1610.com"] [uri "/index.php"] [unique_id "ajCx6fC2Xs1VMQlhsgadtgACLwE"], referer: https://www.google.com/
[Mon Jun 15 20:16:11.423748 2026] [rewrite:error] [pid 51003:tid 51111] [remote 47.79.197.49:16842] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:16:11.533781 2026] [security2:error] [pid 53359:tid 53387] [remote 194.163.139.224:41002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.139.163.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cleantech-holdings.us"] [uri "/wp-login.php"] [unique_id "ajCx6_C2Xs1VMQlhsgad3AACMRU"]
[Mon Jun 15 20:16:11.537100 2026] [security2:error] [pid 51003:tid 51176] [client 109.70.100.8:40474] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "gamergreatness.com"] [uri "/index.php"] [unique_id "ajCx68psKyvb75pkSvaFzQABuno"], referer: https://gamergreatness.com/community/forum/playstation
[Mon Jun 15 20:16:11.698301 2026] [rewrite:error] [pid 51003:tid 51117] [remote 47.79.197.49:16842] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:16:11.807288 2026] [security2:error] [pid 51003:tid 51006] [remote 57.141.14.28:41780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.14.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wilsonoverseas.com"] [uri "/items/G437035876"] [unique_id "ajCx68psKyvb75pkSvaF4QAB_QI"]
[Mon Jun 15 20:16:12.181054 2026] [security2:error] [pid 51003:tid 51177] [client 57.141.14.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "analyticsias.com"] [uri "/index.php"] [unique_id "ajCx68psKyvb75pkSvaF0wAAAbs"]
[Mon Jun 15 20:16:12.443157 2026] [security2:error] [pid 51003:tid 51151] [client 203.94.45.77:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "astonetech.com"] [uri "/index.php"] [unique_id "ajCx6spsKyvb75pkSvaFqgAAAaE"], referer: https://astonetech.com/?utm_source=Pinterest&utm_medium=organic
[Mon Jun 15 20:16:12.705152 2026] [security2:error] [pid 53359:tid 53503] [client 213.180.203.237:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCx7PC2Xs1VMQlhsgad8QAAAhw"]
[Mon Jun 15 20:16:12.710409 2026] [security2:error] [pid 53359:tid 53513] [client 213.180.203.237:41750] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCx7PC2Xs1VMQlhsgad7gACJh4"]
[Mon Jun 15 20:16:12.859197 2026] [security2:error] [pid 53359:tid 53515] [client 192.140.64.94:29539] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCx7PC2Xs1VMQlhsgad9AAAAig"]
[Mon Jun 15 20:16:12.863946 2026] [security2:error] [pid 53359:tid 53515] [client 192.140.64.94:29539] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCx7PC2Xs1VMQlhsgad9AAAAig"]
[Mon Jun 15 20:16:12.888419 2026] [security2:error] [pid 51003:tid 51182] [client 47.79.206.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "societytodaynews.com"] [uri "/index.php"] [unique_id "ajCx7MpsKyvb75pkSvaF-AAAAcA"], referer: https://www.google.com/
[Mon Jun 15 20:16:12.963622 2026] [security2:error] [pid 53359:tid 53507] [client 223.109.252.195:56480] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.diggysguide.com"] [uri "/brush-of-genius/leos-challenge-1"] [unique_id "ajCx7PC2Xs1VMQlhsgad-AAAAiA"]
[Mon Jun 15 20:16:12.963745 2026] [security2:error] [pid 53359:tid 53507] [client 223.109.252.195:56480] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.diggysguide.com"] [uri "/brush-of-genius/leos-challenge-1"] [unique_id "ajCx7PC2Xs1VMQlhsgad-AAAAiA"]
[Mon Jun 15 20:16:13.232142 2026] [security2:error] [pid 51003:tid 51101] [remote 188.166.231.216:42588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.231.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mizukicnc.readerwiz.com"] [uri "/wp-login.php"] [unique_id "ajCx7cpsKyvb75pkSvaGBwABz2E"]
[Mon Jun 15 20:16:13.423764 2026] [security2:error] [pid 53359:tid 53404] [remote 57.141.14.19:53318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCx7fC2Xs1VMQlhsgaeAwACMyY"]
[Mon Jun 15 20:16:13.570952 2026] [security2:error] [pid 53359:tid 53535] [client 43.172.195.176:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCx7fC2Xs1VMQlhsgaeAQACPA8"]
[Mon Jun 15 20:16:13.592687 2026] [security2:error] [pid 53359:tid 53558] [client 5.8.35.241:36068] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "tampapowerwashers.com"] [uri "/wp-login.php"] [unique_id "ajCx7fC2Xs1VMQlhsgaeBgAAAlM"]
[Mon Jun 15 20:16:13.640240 2026] [security2:error] [pid 51003:tid 51110] [remote 188.166.231.216:42588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.231.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mizukicnc.readerwiz.com"] [uri "/wp-login.php"] [unique_id "ajCx7cpsKyvb75pkSvaGDQAB4Go"], referer: https://mizukicnc.readerwiz.com/wp-login.php
[Mon Jun 15 20:16:13.664483 2026] [security2:error] [pid 53359:tid 53403] [remote 128.242.232.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCx7fC2Xs1VMQlhsgaeAAACbyU"], referer: https://mywordsnthoughts.com/reema-lagoo-the-most-popular-screen-mother-of-salman-khan/
[Mon Jun 15 20:16:13.665475 2026] [security2:error] [pid 51003:tid 51131] [remote 213.171.208.62:33002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.208.171.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shaalestate.com"] [uri "/wp-login.php"] [unique_id "ajCx7cpsKyvb75pkSvaGEAACDX8"]
[Mon Jun 15 20:16:13.739690 2026] [security2:error] [pid 53359:tid 53553] [client 128.242.232.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCx7fC2Xs1VMQlhsgaeAgACTh8"], referer: https://mywordsnthoughts.com/reema-lagoo-the-most-popular-screen-mother-of-salman-khan/
[Mon Jun 15 20:16:13.881577 2026] [security2:error] [pid 51003:tid 51004] [remote 213.171.208.62:33002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.208.171.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shaalestate.com"] [uri "/wp-login.php"] [unique_id "ajCx7cpsKyvb75pkSvaGGgAB2QA"], referer: https://shaalestate.com/wp-login.php
[Mon Jun 15 20:16:13.997230 2026] [security2:error] [pid 51003:tid 51186] [client 57.141.14.66:60082] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCx7cpsKyvb75pkSvaGGwABxEk"]
[Mon Jun 15 20:16:14.297422 2026] [security2:error] [pid 51003:tid 51195] [client 68.209.238.169:64827] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.diggysguide.com"] [uri "/index.php"] [unique_id "ajCx7spsKyvb75pkSvaGKwABzSg"]
[Mon Jun 15 20:16:15.285538 2026] [security2:error] [pid 53359:tid 53417] [remote 57.141.14.2:63415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.14.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wilsonoverseas.com"] [uri "/items/G437035876"] [unique_id "ajCx7_C2Xs1VMQlhsgaeMwACZzM"]
[Mon Jun 15 20:16:15.740828 2026] [security2:error] [pid 51003:tid 51260] [client 150.241.237.108:30760] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "swayamadds.com"] [uri "/index.php"] [unique_id "ajCx78psKyvb75pkSvaGTgAAAg4"], referer: https://swayamadds.com/
[Mon Jun 15 20:16:16.127793 2026] [security2:error] [pid 53359:tid 53390] [remote 43.173.176.85:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCx7_C2Xs1VMQlhsgaeOQACMxg"], referer: https://mywordsnthoughts.com/best-biopics-made-on-bollywood-screen/
[Mon Jun 15 20:16:16.161077 2026] [security2:error] [pid 51003:tid 51013] [remote 43.172.194.110:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCx78psKyvb75pkSvaGUQABtwk"], referer: https://mywordsnthoughts.com/best-biopics-made-on-bollywood-screen/
[Mon Jun 15 20:16:16.272076 2026] [security2:error] [pid 51003:tid 51014] [remote 57.141.14.100:46539] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCx8MpsKyvb75pkSvaGVwABzAo"]
[Mon Jun 15 20:16:16.939582 2026] [security2:error] [pid 51003:tid 51244] [client 65.111.30.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.procrastinatingworker.imcorp.in"] [uri "/index.php"] [unique_id "ajCx8MpsKyvb75pkSvaGZwAAAf4"]
[Mon Jun 15 20:16:17.166353 2026] [security2:error] [pid 53359:tid 53426] [remote 57.141.14.103:33768] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCx8fC2Xs1VMQlhsgaeTQACSDw"]
[Mon Jun 15 20:16:17.691595 2026] [security2:error] [pid 53359:tid 53615] [client 47.79.207.247:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "societytodaynews.com"] [uri "/index.php"] [unique_id "ajCx8fC2Xs1VMQlhsgaeVwAAAow"], referer: https://www.google.com/
[Mon Jun 15 20:16:17.824717 2026] [security2:error] [pid 51003:tid 51167] [client 45.3.42.170:26029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.42.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rajunandkardeputycollector.blog"] [uri "/wp-login.php"] [unique_id "ajCx8cpsKyvb75pkSvaGeQAAAbE"], referer: https://rajunandkardeputycollector.blog/wp-login.php
[Mon Jun 15 20:16:18.173277 2026] [security2:error] [pid 53359:tid 53521] [client 52.167.144.234:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.everyads.in"] [uri "/public/index.php"] [unique_id "ajCx8vC2Xs1VMQlhsgaeZwAAAi4"]
[Mon Jun 15 20:16:18.255975 2026] [security2:error] [pid 51003:tid 51055] [remote 20.153.140.50:39390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brahmlagna.com"] [uri "/wp-login.php"] [unique_id "ajCx8spsKyvb75pkSvaGgQABmDM"]
[Mon Jun 15 20:16:18.426940 2026] [security2:error] [pid 53359:tid 53584] [client 45.3.41.86:37101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.41.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rajunandkardeputycollector.blog"] [uri "/wp-login.php"] [unique_id "ajCx8vC2Xs1VMQlhsgaebAAAAm0"], referer: https://rajunandkardeputycollector.blog/wp-login.php
[Mon Jun 15 20:16:18.489369 2026] [security2:error] [pid 51003:tid 51255] [client 31.219.209.201:60637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.209.219.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCx8spsKyvb75pkSvaGigAAAgk"]
[Mon Jun 15 20:16:18.489539 2026] [security2:error] [pid 51003:tid 51255] [client 31.219.209.201:60637] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCx8spsKyvb75pkSvaGigAAAgk"]
[Mon Jun 15 20:16:18.505869 2026] [security2:error] [pid 53359:tid 53516] [client 57.141.14.44:36557] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCx8vC2Xs1VMQlhsgaeawACKUU"]
[Mon Jun 15 20:16:18.685901 2026] [security2:error] [pid 51003:tid 51073] [remote 20.153.140.50:39390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brahmlagna.com"] [uri "/wp-login.php"] [unique_id "ajCx8spsKyvb75pkSvaGjgABrkU"], referer: https://brahmlagna.com/wp-login.php
[Mon Jun 15 20:16:18.851354 2026] [security2:error] [pid 51003:tid 51174] [client 43.173.180.228:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "itdeed.com"] [uri "/demomahayogini/product-tag/dating-books/feed"] [unique_id "ajCx8spsKyvb75pkSvaGlgAAAbg"]
[Mon Jun 15 20:16:18.896995 2026] [security2:error] [pid 53359:tid 53500] [client 43.173.175.176:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "itdeed.com"] [uri "/demomahayogini/product/\\xf0\\x9f\\x94\\xb1-powerful-baglamukhi-puja-for-victory-protection-legal-success"] [unique_id "ajCx8vC2Xs1VMQlhsgaecgAAAhk"]
[Mon Jun 15 20:16:18.993868 2026] [security2:error] [pid 53359:tid 53583] [client 43.172.194.239:39554] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "itdeed.com"] [uri "/demomahayogini/wp-json/oembed/1.0/embed"] [unique_id "ajCx8vC2Xs1VMQlhsgaedQAAAmw"]
[Mon Jun 15 20:16:19.670556 2026] [security2:error] [pid 53359:tid 53498] [client 65.111.30.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.procrastinatingworker.imcorp.in"] [uri "/index.php"] [unique_id "ajCx8_C2Xs1VMQlhsgaefAAAAhc"]
[Mon Jun 15 20:16:20.102642 2026] [security2:error] [pid 53359:tid 53600] [client 57.141.14.92:20406] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCx8_C2Xs1VMQlhsgaehAACfTA"]
[Mon Jun 15 20:16:20.127070 2026] [security2:error] [pid 53359:tid 53545] [client 213.190.10.205:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kthemani.com"] [uri "/index.php"] [unique_id "ajCx8vC2Xs1VMQlhsgaeaAACRkA"]
[Mon Jun 15 20:16:20.464192 2026] [security2:error] [pid 53359:tid 53525] [client 47.128.96.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.weedtale.com"] [uri "/index.php"] [unique_id "ajCx9PC2Xs1VMQlhsgaeiwAAAjI"]
[Mon Jun 15 20:16:20.500807 2026] [security2:error] [pid 53359:tid 53539] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-content/uploads/"] [unique_id "ajCx9PC2Xs1VMQlhsgaekwAAAkA"]
[Mon Jun 15 20:16:20.602407 2026] [security2:error] [pid 53359:tid 53467] [remote 45.117.169.86:44952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.169.117.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "madakasira.in"] [uri "/wp-login.php"] [unique_id "ajCx9PC2Xs1VMQlhsgaevAACXmU"]
[Mon Jun 15 20:16:20.693874 2026] [security2:error] [pid 53359:tid 53621] [client 116.179.32.147:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCx8_C2Xs1VMQlhsgaegwACkkg"]
[Mon Jun 15 20:16:21.178862 2026] [autoindex:error] [pid 53359:tid 53540] [client 82.102.18.118:0] AH01276: Cannot serve directory /home3/itjbthmy/public_html/jcpenneysurvey1/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:16:21.179407 2026] [security2:error] [pid 53359:tid 53540] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCx9fC2Xs1VMQlhsgaeyQAAAkE"]
[Mon Jun 15 20:16:21.183184 2026] [security2:error] [pid 51003:tid 51248] [client 82.102.18.118:43638] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-content/uploads/"] [unique_id "ajCx9cpsKyvb75pkSvaG2AAAAgI"]
[Mon Jun 15 20:16:21.222870 2026] [security2:error] [pid 53359:tid 53503] [client 162.214.80.21:52784] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "itdeed.com"] [uri "/demomahayogini/wp-cron.php"] [unique_id "ajCx9fC2Xs1VMQlhsgaeywAAAhw"]
[Mon Jun 15 20:16:21.226015 2026] [security2:error] [pid 53359:tid 53502] [client 43.172.197.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itdeed.com"] [uri "/demomahayogini/index.php"] [unique_id "ajCx9PC2Xs1VMQlhsgaehwAAAhs"], referer: https://itdeed.com/demomahayogini/product/%f0%9f%94%b1-powerful-baglamukhi-puja-for-victory-protection-legal-success
[Mon Jun 15 20:16:21.229995 2026] [security2:error] [pid 53359:tid 53581] [client 162.214.80.21:52790] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "itdeed.com"] [uri "/demomahayogini/wp-cron.php"] [unique_id "ajCx9fC2Xs1VMQlhsgaezAAAAmo"]
[Mon Jun 15 20:16:21.241387 2026] [security2:error] [pid 53359:tid 53515] [client 162.214.80.21:52794] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "itdeed.com"] [uri "/demomahayogini/wp-cron.php"] [unique_id "ajCx9fC2Xs1VMQlhsgaezQAAAig"]
[Mon Jun 15 20:16:21.244304 2026] [security2:error] [pid 51003:tid 51214] [client 43.173.178.119:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itdeed.com"] [uri "/demomahayogini/index.php"] [unique_id "ajCx88psKyvb75pkSvaGsQAAAeA"], referer: https://itdeed.com/demomahayogini/product-tag/dating-books/feed
[Mon Jun 15 20:16:21.249211 2026] [security2:error] [pid 53359:tid 53556] [client 40.77.167.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCx9PC2Xs1VMQlhsgaewgACUWA"]
[Mon Jun 15 20:16:21.338337 2026] [security2:error] [pid 53359:tid 53607] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-includes/"] [unique_id "ajCx9fC2Xs1VMQlhsgae0AAAAoQ"]
[Mon Jun 15 20:16:21.471508 2026] [security2:error] [pid 51003:tid 51051] [remote 89.252.134.81:35712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.134.252.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "theguidinglightcollective.com"] [uri "/wp-login.php"] [unique_id "ajCx9cpsKyvb75pkSvaG3wABwy8"]
[Mon Jun 15 20:16:21.528389 2026] [autoindex:error] [pid 53359:tid 53508] [client 82.102.18.118:0] AH01276: Cannot serve directory /home3/itjbthmy/public_html/jcpenneysurvey1/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:16:21.528882 2026] [security2:error] [pid 53359:tid 53508] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCx9fC2Xs1VMQlhsgae1gAAAiE"]
[Mon Jun 15 20:16:21.531771 2026] [security2:error] [pid 51003:tid 51189] [client 82.102.18.118:43638] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-includes/"] [unique_id "ajCx9cpsKyvb75pkSvaG4QAAAcc"]
[Mon Jun 15 20:16:21.682232 2026] [security2:error] [pid 53359:tid 53570] [client 47.128.96.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "weedtale.com"] [uri "/index.php"] [unique_id "ajCx9fC2Xs1VMQlhsgaezwAAAl8"]
[Mon Jun 15 20:16:21.685110 2026] [security2:error] [pid 53359:tid 53499] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-includes/css/"] [unique_id "ajCx9fC2Xs1VMQlhsgae3QAAAhg"]
[Mon Jun 15 20:16:21.759122 2026] [security2:error] [pid 53359:tid 53568] [client 57.141.14.98:42796] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fifthestate.agency"] [uri "/index.php"] [unique_id "ajCx9fC2Xs1VMQlhsgae2AACXW0"]
[Mon Jun 15 20:16:21.762128 2026] [security2:error] [pid 53359:tid 53564] [client 57.141.14.91:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aarohiarts.org"] [uri "/index.php"] [unique_id "ajCx9fC2Xs1VMQlhsgae1wAAAlk"]
[Mon Jun 15 20:16:21.801820 2026] [core:error] [pid 51003:tid 51212] [client 143.198.173.96:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jun 15 20:16:21.801840 2026] [core:error] [pid 51003:tid 51212] [client 143.198.173.96:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jun 15 20:16:21.879080 2026] [autoindex:error] [pid 51003:tid 51246] [client 82.102.18.118:0] AH01276: Cannot serve directory /home3/itjbthmy/public_html/jcpenneysurvey1/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:16:21.879630 2026] [security2:error] [pid 51003:tid 51246] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCx9cpsKyvb75pkSvaG6wAAAgA"]
[Mon Jun 15 20:16:21.901466 2026] [security2:error] [pid 51003:tid 51141] [client 82.102.18.118:43638] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-includes/css/"] [unique_id "ajCx9cpsKyvb75pkSvaG6QAAAZc"]
[Mon Jun 15 20:16:21.909063 2026] [security2:error] [pid 51003:tid 51167] [client 57.141.14.91:32214] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCx9cpsKyvb75pkSvaG5gABsUs"]
[Mon Jun 15 20:16:22.030276 2026] [security2:error] [pid 53359:tid 53476] [remote 45.117.169.86:44952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.169.117.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "madakasira.in"] [uri "/wp-login.php"] [unique_id "ajCx9vC2Xs1VMQlhsgae7AACVm4"], referer: https://madakasira.in/wp-login.php
[Mon Jun 15 20:16:22.056983 2026] [security2:error] [pid 53359:tid 53587] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-includes/ID3/"] [unique_id "ajCx9vC2Xs1VMQlhsgae7QAAAnA"]
[Mon Jun 15 20:16:22.312742 2026] [autoindex:error] [pid 53359:tid 53598] [client 82.102.18.118:0] AH01276: Cannot serve directory /home3/itjbthmy/public_html/jcpenneysurvey1/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:16:22.313566 2026] [security2:error] [pid 53359:tid 53598] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCx9vC2Xs1VMQlhsgae9wAAAns"]
[Mon Jun 15 20:16:22.381345 2026] [security2:error] [pid 51003:tid 51196] [client 65.111.30.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.procrastinatingworker.imcorp.in"] [uri "/index.php"] [unique_id "ajCx9spsKyvb75pkSvaG-gAAAc4"]
[Mon Jun 15 20:16:22.390812 2026] [security2:error] [pid 51003:tid 51162] [client 82.102.18.118:43638] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-includes/ID3/"] [unique_id "ajCx9spsKyvb75pkSvaG-QAAAaw"]
[Mon Jun 15 20:16:22.456501 2026] [security2:error] [pid 53359:tid 53480] [remote 64.131.86.2:45566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.86.131.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rajunandkardeputycollector.blog"] [uri "/wp-login.php"] [unique_id "ajCx9vC2Xs1VMQlhsgae_AACSXI"]
[Mon Jun 15 20:16:22.544546 2026] [security2:error] [pid 53359:tid 53619] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-includes/IXR/"] [unique_id "ajCx9vC2Xs1VMQlhsgafCwAAApA"]
[Mon Jun 15 20:16:22.610877 2026] [security2:error] [pid 53359:tid 53478] [remote 66.249.64.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCx9vC2Xs1VMQlhsgae8QACS3A"]
[Mon Jun 15 20:16:22.636655 2026] [security2:error] [pid 51003:tid 51053] [remote 112.196.0.228:35168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.0.196.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ispatalloy.com"] [uri "/wp-login.php"] [unique_id "ajCx9spsKyvb75pkSvaHBAABojE"]
[Mon Jun 15 20:16:22.639269 2026] [security2:error] [pid 53359:tid 53421] [remote 64.131.86.2:45566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.86.131.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rajunandkardeputycollector.blog"] [uri "/wp-login.php"] [unique_id "ajCx9vC2Xs1VMQlhsgafPQACUDc"], referer: https://rajunandkardeputycollector.blog/wp-login.php
[Mon Jun 15 20:16:22.788816 2026] [security2:error] [pid 51003:tid 51110] [remote 89.252.134.81:35712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.134.252.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "theguidinglightcollective.com"] [uri "/wp-login.php"] [unique_id "ajCx9spsKyvb75pkSvaHCQAB7Go"], referer: https://theguidinglightcollective.com/wp-login.php
[Mon Jun 15 20:16:22.800706 2026] [autoindex:error] [pid 53359:tid 53543] [client 82.102.18.118:0] AH01276: Cannot serve directory /home3/itjbthmy/public_html/jcpenneysurvey1/wp-includes/IXR/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:16:22.801200 2026] [security2:error] [pid 53359:tid 53543] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCx9vC2Xs1VMQlhsgafQgAAAkQ"]
[Mon Jun 15 20:16:22.808803 2026] [security2:error] [pid 51003:tid 51139] [client 82.102.18.118:43638] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-includes/IXR/"] [unique_id "ajCx9spsKyvb75pkSvaHCAAAAZU"]
[Mon Jun 15 20:16:22.963192 2026] [security2:error] [pid 53359:tid 53556] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-includes/Requests/"] [unique_id "ajCx9vC2Xs1VMQlhsgafRgAAAlE"]
[Mon Jun 15 20:16:23.194247 2026] [autoindex:error] [pid 53359:tid 53551] [client 82.102.18.118:0] AH01276: Cannot serve directory /home3/itjbthmy/public_html/jcpenneysurvey1/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:16:23.194705 2026] [security2:error] [pid 53359:tid 53551] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCx9_C2Xs1VMQlhsgafUAAAAkw"]
[Mon Jun 15 20:16:23.206891 2026] [security2:error] [pid 51003:tid 51134] [client 82.102.18.118:43638] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-includes/Requests/"] [unique_id "ajCx98psKyvb75pkSvaHEAAAAZA"]
[Mon Jun 15 20:16:23.372902 2026] [security2:error] [pid 53359:tid 53613] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-includes/SimplePie/"] [unique_id "ajCx9_C2Xs1VMQlhsgafWgAAAoo"]
[Mon Jun 15 20:16:23.525220 2026] [security2:error] [pid 51003:tid 51191] [client 192.140.64.94:29639] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCx98psKyvb75pkSvaHFgAAAck"]
[Mon Jun 15 20:16:23.525316 2026] [security2:error] [pid 51003:tid 51191] [client 192.140.64.94:29639] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCx98psKyvb75pkSvaHFgAAAck"]
[Mon Jun 15 20:16:23.568163 2026] [autoindex:error] [pid 51003:tid 51217] [client 82.102.18.118:0] AH01276: Cannot serve directory /home3/itjbthmy/public_html/jcpenneysurvey1/wp-includes/SimplePie/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:16:23.568684 2026] [security2:error] [pid 51003:tid 51217] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCx98psKyvb75pkSvaHGgAAAeM"]
[Mon Jun 15 20:16:23.571725 2026] [security2:error] [pid 51003:tid 51168] [client 82.102.18.118:43638] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-includes/SimplePie/"] [unique_id "ajCx98psKyvb75pkSvaHFwAAAbI"]
[Mon Jun 15 20:16:23.669542 2026] [security2:error] [pid 53359:tid 53609] [client 43.173.180.253:38852] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "itdeed.com"] [uri "/demomahayogini/wp-content/plugins/woocommerce-product-addon/css/bootstrap/bootstrap.css"] [unique_id "ajCx9_C2Xs1VMQlhsgafZAAAAoY"], referer: https://itdeed.com/demomahayogini/product/%F0%9F%94%B1-powerful-baglamukhi-puja-for-victory-protection-legal-success/
[Mon Jun 15 20:16:23.730863 2026] [security2:error] [pid 53359:tid 53596] [client 85.87.163.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kthemani.com"] [uri "/index.php"] [unique_id "ajCx9fC2Xs1VMQlhsgae5AAAAnk"]
[Mon Jun 15 20:16:23.738883 2026] [security2:error] [pid 53359:tid 53511] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-includes/Text/"] [unique_id "ajCx9_C2Xs1VMQlhsgafawAAAiQ"]
[Mon Jun 15 20:16:23.745720 2026] [security2:error] [pid 53359:tid 53618] [client 43.173.181.131:60750] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "itdeed.com"] [uri "/demomahayogini/wp-content/plugins/woocommerce-product-addon/css/ppom-simple-popup.css"] [unique_id "ajCx9_C2Xs1VMQlhsgafbQAAAo8"], referer: https://itdeed.com/demomahayogini/product/%F0%9F%94%B1-powerful-baglamukhi-puja-for-victory-protection-legal-success/
[Mon Jun 15 20:16:23.769735 2026] [security2:error] [pid 53359:tid 53526] [client 43.172.194.114:35938] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "itdeed.com"] [uri "/demomahayogini/wp-content/plugins/woocommerce-product-addon/backend/assets/tooltip/tooltip.css"] [unique_id "ajCx9_C2Xs1VMQlhsgafcAAAAjM"], referer: https://itdeed.com/demomahayogini/product/%F0%9F%94%B1-powerful-baglamukhi-puja-for-victory-protection-legal-success/
[Mon Jun 15 20:16:23.789078 2026] [security2:error] [pid 53359:tid 53586] [client 43.173.179.74:59854] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "itdeed.com"] [uri "/demomahayogini/wp-content/plugins/woocommerce-product-addon/css/bootstrap/bootstrap.modal.css"] [unique_id "ajCx9_C2Xs1VMQlhsgafcQAAAm8"], referer: https://itdeed.com/demomahayogini/product/%F0%9F%94%B1-powerful-baglamukhi-puja-for-victory-protection-legal-success/
[Mon Jun 15 20:16:23.794787 2026] [security2:error] [pid 51003:tid 51091] [remote 57.141.14.92:21966] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCx98psKyvb75pkSvaHHgAB71c"]
[Mon Jun 15 20:16:23.937135 2026] [autoindex:error] [pid 53359:tid 53604] [client 82.102.18.118:0] AH01276: Cannot serve directory /home3/itjbthmy/public_html/jcpenneysurvey1/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:16:23.937602 2026] [security2:error] [pid 53359:tid 53604] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCx9_C2Xs1VMQlhsgafdQAAAoE"]
[Mon Jun 15 20:16:23.943312 2026] [security2:error] [pid 51003:tid 51246] [client 82.102.18.118:43638] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-includes/Text/"] [unique_id "ajCx98psKyvb75pkSvaHIAAAAgA"]
[Mon Jun 15 20:16:24.129902 2026] [security2:error] [pid 53359:tid 53530] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-content/mu-plugins-old/"] [unique_id "ajCx-PC2Xs1VMQlhsgafeAAAAjc"]
[Mon Jun 15 20:16:24.758553 2026] [security2:error] [pid 53359:tid 53578] [client 43.173.177.134:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "itdeed.com"] [uri "/demomahayogini/product-tag/dating-books/feed"] [unique_id "ajCx-PC2Xs1VMQlhsgafigAAAmc"]
[Mon Jun 15 20:16:24.802289 2026] [security2:error] [pid 53359:tid 53497] [client 57.141.14.67:36023] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCx-PC2Xs1VMQlhsgafhwACFk8"]
[Mon Jun 15 20:16:24.872542 2026] [core:error] [pid 53359:tid 53568] [client 143.198.173.96:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.jfoods.co.in/
[Mon Jun 15 20:16:24.872567 2026] [core:error] [pid 53359:tid 53568] [client 143.198.173.96:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.jfoods.co.in/
[Mon Jun 15 20:16:25.174457 2026] [security2:error] [pid 51003:tid 51236] [client 65.111.30.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.procrastinatingworker.imcorp.in"] [uri "/index.php"] [unique_id "ajCx-cpsKyvb75pkSvaHPAAAAfY"]
[Mon Jun 15 20:16:25.571684 2026] [security2:error] [pid 53359:tid 53409] [remote 47.128.32.44:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mywordsnthoughts.com"] [uri "/david-dhawan-the-director-behind-brainless-comedy-entertainers-of-bollywood/"] [unique_id "ajCx-fC2Xs1VMQlhsgafmwAChis"]
[Mon Jun 15 20:16:25.634423 2026] [security2:error] [pid 51003:tid 51023] [remote 112.196.0.228:35168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.0.196.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ispatalloy.com"] [uri "/wp-login.php"] [unique_id "ajCx-cpsKyvb75pkSvaHQwABxBM"], referer: https://ispatalloy.com/wp-login.php
[Mon Jun 15 20:16:25.909067 2026] [security2:error] [pid 51003:tid 51208] [client 82.102.18.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCx-MpsKyvb75pkSvaHLAAAAdo"]
[Mon Jun 15 20:16:25.909093 2026] [security2:error] [pid 51003:tid 51208] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCx-MpsKyvb75pkSvaHLAAAAdo"]
[Mon Jun 15 20:16:26.026407 2026] [security2:error] [pid 51003:tid 51195] [client 82.102.18.118:43638] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-content/mu-plugins-old/"] [unique_id "ajCx-MpsKyvb75pkSvaHKgAAAc0"]
[Mon Jun 15 20:16:26.199834 2026] [core:crit] [pid 53359:tid 53617] (13)Permission denied: [client 43.160.219.138:57620] AH00529: /home4/tqashde3/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home4/tqashde3/' is executable
[Mon Jun 15 20:16:26.345767 2026] [security2:error] [pid 53359:tid 53574] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-content/themes/classic/inc/"] [unique_id "ajCx-vC2Xs1VMQlhsgaftAAAAmM"]
[Mon Jun 15 20:16:26.592565 2026] [security2:error] [pid 51003:tid 51159] [client 45.84.107.198:39909] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "gamergreatness.com"] [uri "/index.php"] [unique_id "ajCx-spsKyvb75pkSvaHTgABqWU"], referer: https://gamergreatness.com/community/forum/tech
[Mon Jun 15 20:16:26.736059 2026] [security2:error] [pid 51003:tid 51221] [client 57.141.14.62:30674] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCx-spsKyvb75pkSvaHUQAB50M"]
[Mon Jun 15 20:16:26.787441 2026] [security2:error] [pid 51003:tid 51166] [client 143.244.57.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.surveylaya.com"] [uri "/wp-content/index.php"] [unique_id "ajCx-spsKyvb75pkSvaHVQAAAbA"]
[Mon Jun 15 20:16:26.793134 2026] [security2:error] [pid 53359:tid 53563] [client 143.244.57.120:40718] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.surveylaya.com"] [uri "/wp-content/"] [unique_id "ajCx-vC2Xs1VMQlhsgafwwAAAlg"]
[Mon Jun 15 20:16:26.807271 2026] [security2:error] [pid 53359:tid 53561] [client 82.102.18.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCx-vC2Xs1VMQlhsgafvgAAAlY"]
[Mon Jun 15 20:16:26.807296 2026] [security2:error] [pid 53359:tid 53561] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCx-vC2Xs1VMQlhsgafvgAAAlY"]
[Mon Jun 15 20:16:26.877218 2026] [security2:error] [pid 51003:tid 51163] [client 82.102.18.118:43638] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-content/themes/classic/inc/"] [unique_id "ajCx-spsKyvb75pkSvaHUAAAAa0"]
[Mon Jun 15 20:16:27.038479 2026] [security2:error] [pid 53359:tid 53535] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-content/plugins/ninja-forms/"] [unique_id "ajCx-_C2Xs1VMQlhsgafxwAAAjw"]
[Mon Jun 15 20:16:27.493071 2026] [security2:error] [pid 53359:tid 53616] [client 82.102.18.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCx-_C2Xs1VMQlhsgafzwAAAo0"]
[Mon Jun 15 20:16:27.493098 2026] [security2:error] [pid 53359:tid 53616] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCx-_C2Xs1VMQlhsgafzwAAAo0"]
[Mon Jun 15 20:16:27.503122 2026] [security2:error] [pid 51003:tid 51142] [client 82.102.18.118:43638] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-content/plugins/ninja-forms/"] [unique_id "ajCx-8psKyvb75pkSvaHYAAAAZg"]
[Mon Jun 15 20:16:27.589267 2026] [security2:error] [pid 53359:tid 53505] [client 92.132.211.135:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kthemani.com"] [uri "/index.php"] [unique_id "ajCx-fC2Xs1VMQlhsgafnAACHkw"]
[Mon Jun 15 20:16:27.671919 2026] [security2:error] [pid 53359:tid 53530] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-content/mu-plugins/"] [unique_id "ajCx-_C2Xs1VMQlhsgaf1QAAAjc"]
[Mon Jun 15 20:16:27.710503 2026] [security2:error] [pid 51003:tid 51093] [remote 89.58.31.106:34138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.31.58.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muditathaispa.com"] [uri "/wp-login.php"] [unique_id "ajCx-8psKyvb75pkSvaHZQAB7Vk"]
[Mon Jun 15 20:16:27.869360 2026] [security2:error] [pid 53359:tid 53608] [client 65.111.30.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.procrastinatingworker.imcorp.in"] [uri "/index.php"] [unique_id "ajCx-_C2Xs1VMQlhsgaf3AAAAoU"]
[Mon Jun 15 20:16:27.872699 2026] [autoindex:error] [pid 53359:tid 53545] [client 82.102.18.118:0] AH01276: Cannot serve directory /home3/itjbthmy/public_html/jcpenneysurvey1/wp-content/mu-plugins/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:16:27.873145 2026] [security2:error] [pid 53359:tid 53545] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCx-_C2Xs1VMQlhsgaf3wAAAkY"]
[Mon Jun 15 20:16:27.876898 2026] [security2:error] [pid 51003:tid 51146] [client 82.102.18.118:43638] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-content/mu-plugins/"] [unique_id "ajCx-8psKyvb75pkSvaHagAAAZw"]
[Mon Jun 15 20:16:27.903477 2026] [security2:error] [pid 51003:tid 51065] [remote 89.58.31.106:34138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.31.58.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muditathaispa.com"] [uri "/wp-login.php"] [unique_id "ajCx-8psKyvb75pkSvaHbwABmj0"], referer: https://muditathaispa.com/wp-login.php
[Mon Jun 15 20:16:27.963541 2026] [security2:error] [pid 53359:tid 53476] [remote 57.141.14.42:30764] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCx-_C2Xs1VMQlhsgaf3gACjm4"]
[Mon Jun 15 20:16:28.030204 2026] [security2:error] [pid 53359:tid 53512] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-includes/Text/Diff/Renderer/"] [unique_id "ajCx_PC2Xs1VMQlhsgaf6AAAAiU"]
[Mon Jun 15 20:16:28.130965 2026] [security2:error] [pid 53359:tid 53452] [remote 110.249.201.217:25466] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "puzzleadventureguide.com"] [uri "/en/the-prince/old-quarry"] [unique_id "ajCx_PC2Xs1VMQlhsgaf6gACKlY"]
[Mon Jun 15 20:16:28.199708 2026] [security2:error] [pid 53359:tid 53499] [client 65.111.28.147:15737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.28.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rajunandkardeputycollector.blog"] [uri "/wp-login.php"] [unique_id "ajCx_PC2Xs1VMQlhsgaf6wAAAhg"], referer: https://rajunandkardeputycollector.blog/wp-login.php
[Mon Jun 15 20:16:28.243337 2026] [security2:error] [pid 53359:tid 53554] [client 47.84.60.139:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "itdeed.com"] [uri "/demomahayogini/product-tag/dating-books/feed"] [unique_id "ajCx_PC2Xs1VMQlhsgaf7wAAAk8"]
[Mon Jun 15 20:16:28.254047 2026] [autoindex:error] [pid 53359:tid 53536] [client 82.102.18.118:0] AH01276: Cannot serve directory /home3/itjbthmy/public_html/jcpenneysurvey1/wp-includes/Text/Diff/Renderer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:16:28.254498 2026] [security2:error] [pid 53359:tid 53536] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCx_PC2Xs1VMQlhsgaf7gAAAj0"]
[Mon Jun 15 20:16:28.273483 2026] [security2:error] [pid 51003:tid 51152] [client 82.102.18.118:43638] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-includes/Text/Diff/Renderer/"] [unique_id "ajCx_MpsKyvb75pkSvaHdAAAAaI"]
[Mon Jun 15 20:16:28.430469 2026] [security2:error] [pid 53359:tid 53567] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-includes/blocks/"] [unique_id "ajCx_PC2Xs1VMQlhsgaf8wAAAlw"]
[Mon Jun 15 20:16:28.598637 2026] [security2:error] [pid 51003:tid 51149] [client 143.244.57.88:55952] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "rkfreshmart.net"] [uri "/wp-content/index.php"] [unique_id "ajCx_MpsKyvb75pkSvaHegAAAZ8"]
[Mon Jun 15 20:16:28.754371 2026] [security2:error] [pid 51003:tid 51182] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-includes/blocks/index.php"] [unique_id "ajCx_MpsKyvb75pkSvaHggAAAcA"]
[Mon Jun 15 20:16:28.779507 2026] [security2:error] [pid 51003:tid 51255] [client 82.102.18.118:43638] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-includes/blocks/"] [unique_id "ajCx_MpsKyvb75pkSvaHewAAAgk"]
[Mon Jun 15 20:16:28.933085 2026] [security2:error] [pid 53359:tid 53500] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-includes/certificates/"] [unique_id "ajCx_PC2Xs1VMQlhsgaf_AAAAhk"]
[Mon Jun 15 20:16:28.963500 2026] [security2:error] [pid 51003:tid 51218] [client 45.3.43.96:11401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.43.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rajunandkardeputycollector.blog"] [uri "/wp-login.php"] [unique_id "ajCx_MpsKyvb75pkSvaHhwAAAeQ"], referer: https://rajunandkardeputycollector.blog/wp-login.php
[Mon Jun 15 20:16:29.073091 2026] [security2:error] [pid 51003:tid 51244] [client 31.219.209.201:61247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.209.219.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCx_cpsKyvb75pkSvaHiQAAAf4"]
[Mon Jun 15 20:16:29.073184 2026] [security2:error] [pid 51003:tid 51244] [client 31.219.209.201:61247] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCx_cpsKyvb75pkSvaHiQAAAf4"]
[Mon Jun 15 20:16:29.125994 2026] [autoindex:error] [pid 51003:tid 51219] [client 82.102.18.118:0] AH01276: Cannot serve directory /home3/itjbthmy/public_html/jcpenneysurvey1/wp-includes/certificates/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:16:29.126635 2026] [security2:error] [pid 51003:tid 51219] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCx_cpsKyvb75pkSvaHjAAAAeU"]
[Mon Jun 15 20:16:29.128085 2026] [security2:error] [pid 51003:tid 51192] [client 82.102.18.118:43638] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-includes/certificates/"] [unique_id "ajCx_cpsKyvb75pkSvaHigAAAco"]
[Mon Jun 15 20:16:29.295719 2026] [security2:error] [pid 53359:tid 53603] [client 45.84.107.198:39913] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "gamergreatness.com"] [uri "/index.php"] [unique_id "ajCx_fC2Xs1VMQlhsgaf_wACgHo"], referer: https://gamergreatness.com/community/forum/xbox
[Mon Jun 15 20:16:29.321250 2026] [security2:error] [pid 53359:tid 53542] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-includes/customize/"] [unique_id "ajCx_fC2Xs1VMQlhsgagEAAAAkM"]
[Mon Jun 15 20:16:29.371127 2026] [security2:error] [pid 51003:tid 51085] [remote 57.141.14.54:25197] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCx_cpsKyvb75pkSvaHkwABz1E"]
[Mon Jun 15 20:16:29.499466 2026] [security2:error] [pid 53359:tid 53528] [client 104.207.35.199:25529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.35.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rajunandkardeputycollector.blog"] [uri "/wp-login.php"] [unique_id "ajCx_fC2Xs1VMQlhsgagHwAAAjU"], referer: https://rajunandkardeputycollector.blog/wp-login.php
[Mon Jun 15 20:16:29.513588 2026] [autoindex:error] [pid 51003:tid 51257] [client 82.102.18.118:0] AH01276: Cannot serve directory /home3/itjbthmy/public_html/jcpenneysurvey1/wp-includes/customize/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:16:29.514040 2026] [security2:error] [pid 51003:tid 51257] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCx_cpsKyvb75pkSvaHoAAAAgs"]
[Mon Jun 15 20:16:29.518871 2026] [security2:error] [pid 51003:tid 51151] [client 82.102.18.118:43638] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-includes/customize/"] [unique_id "ajCx_cpsKyvb75pkSvaHnQAAAaE"]
[Mon Jun 15 20:16:29.685610 2026] [security2:error] [pid 53359:tid 53579] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-includes/fonts/"] [unique_id "ajCx_fC2Xs1VMQlhsgagJgAAAmg"]
[Mon Jun 15 20:16:29.692016 2026] [security2:error] [pid 53359:tid 53379] [remote 2a03:2880:f806:b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ruchini.hemani.finance"] [uri "/index.php"] [unique_id "ajCx_fC2Xs1VMQlhsgagIwACXw0"]
[Mon Jun 15 20:16:29.901852 2026] [autoindex:error] [pid 51003:tid 51201] [client 82.102.18.118:0] AH01276: Cannot serve directory /home3/itjbthmy/public_html/jcpenneysurvey1/wp-includes/fonts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:16:29.902329 2026] [security2:error] [pid 51003:tid 51201] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCx_cpsKyvb75pkSvaHqgAAAdM"]
[Mon Jun 15 20:16:29.905535 2026] [security2:error] [pid 51003:tid 51162] [client 82.102.18.118:43638] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-includes/fonts/"] [unique_id "ajCx_cpsKyvb75pkSvaHpQAAAaw"]
[Mon Jun 15 20:16:30.049496 2026] [security2:error] [pid 51003:tid 51146] [client 104.207.39.244:14747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.39.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rajunandkardeputycollector.blog"] [uri "/wp-login.php"] [unique_id "ajCx_spsKyvb75pkSvaHsAAAAZw"], referer: https://rajunandkardeputycollector.blog/wp-login.php
[Mon Jun 15 20:16:30.061003 2026] [security2:error] [pid 53359:tid 53613] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-includes/images/"] [unique_id "ajCx_vC2Xs1VMQlhsgagNgAAAoo"]
[Mon Jun 15 20:16:30.116349 2026] [security2:error] [pid 51003:tid 51239] [client 57.141.14.103:34054] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCx_spsKyvb75pkSvaHrgAB-T8"]
[Mon Jun 15 20:16:30.305971 2026] [autoindex:error] [pid 53359:tid 53572] [client 82.102.18.118:0] AH01276: Cannot serve directory /home3/itjbthmy/public_html/jcpenneysurvey1/wp-includes/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:16:30.306660 2026] [security2:error] [pid 53359:tid 53572] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCx_vC2Xs1VMQlhsgagOwAAAmE"]
[Mon Jun 15 20:16:30.322880 2026] [security2:error] [pid 51003:tid 51173] [client 40.77.167.26:63143] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "wantpg.com"] [uri "/public/index.php/in/bayuran-yogyakarta-indonesia-980202.html"] [unique_id "ajCx_spsKyvb75pkSvaHuQABtwg"]
[Mon Jun 15 20:16:30.349953 2026] [security2:error] [pid 51003:tid 51194] [client 82.102.18.118:43638] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-includes/images/"] [unique_id "ajCx_spsKyvb75pkSvaHtgAAAcw"]
[Mon Jun 15 20:16:30.550809 2026] [autoindex:error] [pid 53359:tid 53569] [client 82.102.18.118:0] AH01276: Cannot serve directory /home3/itjbthmy/public_html/jcpenneysurvey1/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:16:30.551571 2026] [security2:error] [pid 53359:tid 53569] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCx_vC2Xs1VMQlhsgagQAAAAl4"]
[Mon Jun 15 20:16:30.560773 2026] [security2:error] [pid 53359:tid 53523] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/.well-known/"] [unique_id "ajCx_vC2Xs1VMQlhsgagPgAAAjA"]
[Mon Jun 15 20:16:30.642248 2026] [security2:error] [pid 51003:tid 51199] [client 104.207.48.188:11005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.48.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rajunandkardeputycollector.blog"] [uri "/wp-login.php"] [unique_id "ajCx_spsKyvb75pkSvaHvwAAAdE"], referer: https://rajunandkardeputycollector.blog/wp-login.php
[Mon Jun 15 20:16:30.731534 2026] [security2:error] [pid 53359:tid 53530] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/ALFA_DATA/"] [unique_id "ajCx_vC2Xs1VMQlhsgagRgAAAjc"]
[Mon Jun 15 20:16:30.744602 2026] [security2:error] [pid 53359:tid 53526] [client 57.141.14.73:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blogliterati.com"] [uri "/index.php"] [unique_id "ajCx_fC2Xs1VMQlhsgagLgAAAjM"]
[Mon Jun 15 20:16:30.894114 2026] [security2:error] [pid 51003:tid 51213] [client 43.172.196.6:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "itdeed.com"] [uri "/demomahayogini/product/\\xf0\\x9f\\x94\\xb1-powerful-baglamukhi-puja-for-victory-protection-legal-success"] [unique_id "ajCx_spsKyvb75pkSvaHxQAAAd8"]
[Mon Jun 15 20:16:31.163253 2026] [security2:error] [pid 53359:tid 53596] [client 57.141.14.105:57510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fifthestate.agency"] [uri "/index.php"] [unique_id "ajCx_vC2Xs1VMQlhsgagSgACeRo"]
[Mon Jun 15 20:16:31.211675 2026] [security2:error] [pid 51003:tid 51254] [client 43.173.182.216:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCx_spsKyvb75pkSvaHygACCGs"]
[Mon Jun 15 20:16:31.241174 2026] [security2:error] [pid 51003:tid 51219] [client 82.102.18.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCx_spsKyvb75pkSvaHywAAAeU"]
[Mon Jun 15 20:16:31.241201 2026] [security2:error] [pid 51003:tid 51219] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCx_spsKyvb75pkSvaHywAAAeU"]
[Mon Jun 15 20:16:31.245707 2026] [security2:error] [pid 51003:tid 51217] [client 82.102.18.118:43638] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/ALFA_DATA/"] [unique_id "ajCx_spsKyvb75pkSvaHyQAAAeM"]
[Mon Jun 15 20:16:31.428984 2026] [security2:error] [pid 53359:tid 53578] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/.well-knownold/"] [unique_id "ajCx__C2Xs1VMQlhsgagVwAAAmc"]
[Mon Jun 15 20:16:31.582709 2026] [security2:error] [pid 53359:tid 53540] [client 45.84.107.198:11545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "gamergreatness.com"] [uri "/index.php"] [unique_id "ajCx__C2Xs1VMQlhsgagVgACQRQ"], referer: https://gamergreatness.com/community/topic/gaming-memes
[Mon Jun 15 20:16:31.878020 2026] [security2:error] [pid 53359:tid 53612] [client 82.102.18.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCx__C2Xs1VMQlhsgagXwAAAok"]
[Mon Jun 15 20:16:31.878044 2026] [security2:error] [pid 53359:tid 53612] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCx__C2Xs1VMQlhsgagXwAAAok"]
[Mon Jun 15 20:16:31.898229 2026] [security2:error] [pid 51003:tid 51138] [client 82.102.18.118:43638] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/.well-knownold/"] [unique_id "ajCx_8psKyvb75pkSvaH2wAAAZQ"]
[Mon Jun 15 20:16:31.927626 2026] [security2:error] [pid 53359:tid 53598] [client 91.186.250.221:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kthemani.com"] [uri "/index.php"] [unique_id "ajCx_vC2Xs1VMQlhsgagNAAAAns"]
[Mon Jun 15 20:16:32.086781 2026] [autoindex:error] [pid 53359:tid 53594] [client 82.102.18.118:0] AH01276: Cannot serve directory /home3/itjbthmy/public_html/jcpenneysurvey1/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:16:32.087208 2026] [security2:error] [pid 53359:tid 53594] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCyAPC2Xs1VMQlhsgagdAAAAnc"]
[Mon Jun 15 20:16:32.090569 2026] [security2:error] [pid 53359:tid 53525] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/.well-known/acme-challenge/"] [unique_id "ajCyAPC2Xs1VMQlhsgagcwAAAjI"]
[Mon Jun 15 20:16:32.239109 2026] [security2:error] [pid 53359:tid 53415] [remote 35.247.151.219:39978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.151.247.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.d-lloydmembershipcost.co.uk"] [uri "/wp-login.php"] [unique_id "ajCyAPC2Xs1VMQlhsgagdwACKTE"]
[Mon Jun 15 20:16:32.244996 2026] [security2:error] [pid 53359:tid 53553] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/cgi-bin/"] [unique_id "ajCyAPC2Xs1VMQlhsgageAAAAk4"]
[Mon Jun 15 20:16:32.296047 2026] [security2:error] [pid 51003:tid 51036] [remote 57.141.14.45:63526] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyAMpsKyvb75pkSvaH5wABmiA"]
[Mon Jun 15 20:16:32.460875 2026] [cgid:error] [pid 51003:tid 51183] [client 82.102.18.118:0] AH01265: stderr from /home3/itjbthmy/public_html/jcpenneysurvey1/cgi-bin/: attempt to invoke directory as script
[Mon Jun 15 20:16:32.461353 2026] [security2:error] [pid 51003:tid 51183] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCyAMpsKyvb75pkSvaH8wAAAcE"]
[Mon Jun 15 20:16:32.510427 2026] [security2:error] [pid 51003:tid 51171] [client 82.102.18.118:43638] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/cgi-bin/"] [unique_id "ajCyAMpsKyvb75pkSvaH8QAAAbU"]
[Mon Jun 15 20:16:32.663281 2026] [security2:error] [pid 53359:tid 53603] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index/"] [unique_id "ajCyAPC2Xs1VMQlhsgaghAAAAoA"]
[Mon Jun 15 20:16:32.767441 2026] [security2:error] [pid 51003:tid 51033] [remote 209.42.18.223:43542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newrajdhanilogistics.com"] [uri "/wp-login.php"] [unique_id "ajCyAMpsKyvb75pkSvaH-QABzB0"]
[Mon Jun 15 20:16:33.080077 2026] [security2:error] [pid 51003:tid 51150] [client 82.102.18.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyAMpsKyvb75pkSvaH-wAAAaA"]
[Mon Jun 15 20:16:33.080098 2026] [security2:error] [pid 51003:tid 51150] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyAMpsKyvb75pkSvaH-wAAAaA"]
[Mon Jun 15 20:16:33.083727 2026] [security2:error] [pid 51003:tid 51177] [client 82.102.18.118:43638] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index/"] [unique_id "ajCyAMpsKyvb75pkSvaH-gAAAbs"]
[Mon Jun 15 20:16:33.244561 2026] [security2:error] [pid 53359:tid 53604] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/id/"] [unique_id "ajCyAfC2Xs1VMQlhsgagiwAAAoE"]
[Mon Jun 15 20:16:33.543116 2026] [security2:error] [pid 53359:tid 53568] [client 47.84.60.139:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "itdeed.com"] [uri "/demomahayogini/product/\\xf0\\x9f\\x94\\xb1-powerful-baglamukhi-puja-for-victory-protection-legal-success"] [unique_id "ajCyAfC2Xs1VMQlhsgaglAAAAl0"]
[Mon Jun 15 20:16:33.693089 2026] [security2:error] [pid 53359:tid 53508] [client 82.102.18.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyAfC2Xs1VMQlhsgagkgAAAiE"]
[Mon Jun 15 20:16:33.693109 2026] [security2:error] [pid 53359:tid 53508] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyAfC2Xs1VMQlhsgagkgAAAiE"]
[Mon Jun 15 20:16:33.700886 2026] [security2:error] [pid 51003:tid 51147] [client 82.102.18.118:43638] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/id/"] [unique_id "ajCyAcpsKyvb75pkSvaICQAAAZ0"]
[Mon Jun 15 20:16:33.794004 2026] [security2:error] [pid 53359:tid 53478] [remote 57.141.14.83:61992] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyAfC2Xs1VMQlhsgagmQACkXA"]
[Mon Jun 15 20:16:33.861190 2026] [security2:error] [pid 53359:tid 53563] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/www/"] [unique_id "ajCyAfC2Xs1VMQlhsgagnQAAAlg"]
[Mon Jun 15 20:16:33.907449 2026] [security2:error] [pid 53359:tid 53509] [client 45.84.107.198:11549] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "gamergreatness.com"] [uri "/index.php"] [unique_id "ajCyAfC2Xs1VMQlhsgagmgACIjc"], referer: https://gamergreatness.com/community/topic/share-your-gaming-setups
[Mon Jun 15 20:16:33.935477 2026] [security2:error] [pid 53359:tid 53534] [client 192.140.64.94:29619] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCyAfC2Xs1VMQlhsgagnwAAAjs"]
[Mon Jun 15 20:16:33.935693 2026] [security2:error] [pid 53359:tid 53534] [client 192.140.64.94:29619] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCyAfC2Xs1VMQlhsgagnwAAAjs"]
[Mon Jun 15 20:16:34.078744 2026] [security2:error] [pid 51003:tid 51077] [remote 68.183.22.192:45708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.22.183.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tec2art.com"] [uri "/wp-login.php"] [unique_id "ajCyAspsKyvb75pkSvaIFQABuUk"]
[Mon Jun 15 20:16:34.239176 2026] [security2:error] [pid 53359:tid 53543] [client 47.79.201.195:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "brainstrom.org"] [uri "/index.php"] [unique_id "ajCyAfC2Xs1VMQlhsgagngACRCk"], referer: https://www.google.com/
[Mon Jun 15 20:16:34.284251 2026] [security2:error] [pid 51003:tid 51246] [client 82.102.18.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyAspsKyvb75pkSvaIFgAAAgA"]
[Mon Jun 15 20:16:34.284277 2026] [security2:error] [pid 51003:tid 51246] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyAspsKyvb75pkSvaIFgAAAgA"]
[Mon Jun 15 20:16:34.293472 2026] [security2:error] [pid 51003:tid 51155] [client 82.102.18.118:43638] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/www/"] [unique_id "ajCyAspsKyvb75pkSvaIEwAAAaU"]
[Mon Jun 15 20:16:34.352699 2026] [security2:error] [pid 53359:tid 53554] [client 134.236.18.247:41748] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "www.newyork-gyms.com"] [uri "/wp-comments-post.php"] [unique_id "ajCyAvC2Xs1VMQlhsgagpwAAAk8"]
[Mon Jun 15 20:16:34.463139 2026] [security2:error] [pid 51003:tid 51122] [remote 178.62.89.9:58528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.89.62.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.kdmfoundation.in"] [uri "/wp-login.php"] [unique_id "ajCyAspsKyvb75pkSvaIJgABqXY"]
[Mon Jun 15 20:16:34.538497 2026] [security2:error] [pid 51003:tid 51215] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-content/cache/wp-rocket/www.jcpenneysurvey.survey-survey.com/index-https.html"] [unique_id "ajCyAspsKyvb75pkSvaILQAAAeE"]
[Mon Jun 15 20:16:34.587744 2026] [security2:error] [pid 51003:tid 51240] [client 82.102.18.118:43638] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/"] [unique_id "ajCyAspsKyvb75pkSvaIJwAAAfo"]
[Mon Jun 15 20:16:34.605949 2026] [security2:error] [pid 53359:tid 53432] [remote 31.3.241.131:53088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.241.3.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tcspune.in"] [uri "/wp-login.php"] [unique_id "ajCyAvC2Xs1VMQlhsgagrQACc0I"]
[Mon Jun 15 20:16:34.642239 2026] [security2:error] [pid 51003:tid 51118] [remote 178.62.89.9:58528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.89.62.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.kdmfoundation.in"] [uri "/wp-login.php"] [unique_id "ajCyAspsKyvb75pkSvaIMQAB9XI"], referer: https://mail.kdmfoundation.in/wp-login.php
[Mon Jun 15 20:16:34.724910 2026] [security2:error] [pid 53359:tid 53554] [client 134.236.18.247:41748] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "www.newyork-gyms.com"] [uri "/wp-comments-post.php"] [unique_id "ajCyAvC2Xs1VMQlhsgagpwAAAk8"]
[Mon Jun 15 20:16:34.724963 2026] [security2:error] [pid 53359:tid 53554] [client 134.236.18.247:41748] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.newyork-gyms.com"] [uri "/wp-comments-post.php"] [unique_id "ajCyAvC2Xs1VMQlhsgagpwAAAk8"]
[Mon Jun 15 20:16:34.742367 2026] [security2:error] [pid 53359:tid 53516] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/web/"] [unique_id "ajCyAvC2Xs1VMQlhsgagrwAAAik"]
[Mon Jun 15 20:16:34.821877 2026] [security2:error] [pid 53359:tid 53437] [remote 31.3.241.131:53088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.241.3.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tcspune.in"] [uri "/wp-login.php"] [unique_id "ajCyAvC2Xs1VMQlhsgagsQACbkc"], referer: https://tcspune.in/wp-login.php
[Mon Jun 15 20:16:35.164528 2026] [security2:error] [pid 51003:tid 51094] [remote 68.183.22.192:45708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.22.183.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tec2art.com"] [uri "/wp-login.php"] [unique_id "ajCyA8psKyvb75pkSvaITAABllo"], referer: https://tec2art.com/wp-login.php
[Mon Jun 15 20:16:35.209745 2026] [security2:error] [pid 53359:tid 53526] [client 82.102.18.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyAvC2Xs1VMQlhsgagtgAAAjM"]
[Mon Jun 15 20:16:35.209785 2026] [security2:error] [pid 53359:tid 53526] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyAvC2Xs1VMQlhsgagtgAAAjM"]
[Mon Jun 15 20:16:35.218617 2026] [security2:error] [pid 51003:tid 51236] [client 82.102.18.118:43638] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/web/"] [unique_id "ajCyAspsKyvb75pkSvaIRgAAAfY"]
[Mon Jun 15 20:16:35.237483 2026] [security2:error] [pid 53359:tid 53430] [remote 57.141.14.79:42680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyA_C2Xs1VMQlhsgaguAACQ0A"]
[Mon Jun 15 20:16:35.249778 2026] [security2:error] [pid 51003:tid 51248] [client 103.125.146.57:59879] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/"] [unique_id "ajCyA8psKyvb75pkSvaITwAAAgI"]
[Mon Jun 15 20:16:35.410938 2026] [security2:error] [pid 53359:tid 53577] [client 57.141.14.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kthemani.com"] [uri "/index.php"] [unique_id "ajCyAfC2Xs1VMQlhsgagkQAAAmY"]
[Mon Jun 15 20:16:35.427733 2026] [security2:error] [pid 53359:tid 53507] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/uploads/"] [unique_id "ajCyA_C2Xs1VMQlhsgagvwAAAiA"]
[Mon Jun 15 20:16:35.696116 2026] [security2:error] [pid 53359:tid 53576] [client 103.125.146.45:39497] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "ajCyA_C2Xs1VMQlhsgagxwAAAmU"]
[Mon Jun 15 20:16:35.870731 2026] [security2:error] [pid 53359:tid 53524] [client 82.102.18.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyA_C2Xs1VMQlhsgagxQAAAjE"]
[Mon Jun 15 20:16:35.870770 2026] [security2:error] [pid 53359:tid 53524] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyA_C2Xs1VMQlhsgagxQAAAjE"]
[Mon Jun 15 20:16:35.885284 2026] [security2:error] [pid 51003:tid 51229] [client 82.102.18.118:43638] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/uploads/"] [unique_id "ajCyA8psKyvb75pkSvaIVwAAAe8"]
[Mon Jun 15 20:16:35.956224 2026] [security2:error] [pid 53359:tid 53537] [client 134.236.18.247:41880] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "www.newyork-gyms.com"] [uri "/wp-comments-post.php"] [unique_id "ajCyA_C2Xs1VMQlhsgag0AAAAj4"]
[Mon Jun 15 20:16:36.043276 2026] [security2:error] [pid 53359:tid 53540] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/upload/"] [unique_id "ajCyBPC2Xs1VMQlhsgag0QAAAkE"]
[Mon Jun 15 20:16:36.092534 2026] [security2:error] [pid 53359:tid 53613] [client 103.125.146.39:64373] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/admin.php"] [unique_id "ajCyBPC2Xs1VMQlhsgag1AAAAoo"]
[Mon Jun 15 20:16:36.143544 2026] [security2:error] [pid 51003:tid 51246] [client 66.249.79.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "legaleye.in"] [uri "/index.php"] [unique_id "ajCyA8psKyvb75pkSvaIZQAAAgA"]
[Mon Jun 15 20:16:36.269667 2026] [security2:error] [pid 53359:tid 53537] [client 134.236.18.247:41880] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "www.newyork-gyms.com"] [uri "/wp-comments-post.php"] [unique_id "ajCyA_C2Xs1VMQlhsgag0AAAAj4"]
[Mon Jun 15 20:16:36.322763 2026] [security2:error] [pid 53359:tid 53544] [client 57.141.14.51:59722] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyBPC2Xs1VMQlhsgag1gACRWs"]
[Mon Jun 15 20:16:36.433397 2026] [security2:error] [pid 51003:tid 51240] [client 47.79.200.193:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "societytodaynews.com"] [uri "/index.php"] [unique_id "ajCyBMpsKyvb75pkSvaIcAAAAfo"], referer: https://www.google.com/
[Mon Jun 15 20:16:36.475853 2026] [security2:error] [pid 51003:tid 51152] [client 143.198.138.196:64638] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "shriganapathisourses.com"] [uri "/wp-login.php"] [unique_id "ajCyBMpsKyvb75pkSvaIewAAAaI"]
[Mon Jun 15 20:16:36.497133 2026] [security2:error] [pid 53359:tid 53560] [client 82.102.18.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyBPC2Xs1VMQlhsgag2gAAAlU"]
[Mon Jun 15 20:16:36.497165 2026] [security2:error] [pid 53359:tid 53560] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyBPC2Xs1VMQlhsgag2gAAAlU"]
[Mon Jun 15 20:16:36.515074 2026] [security2:error] [pid 51003:tid 51171] [client 103.125.146.43:49853] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/edit-tags.php"] [unique_id "ajCyBMpsKyvb75pkSvaIfQAAAbU"]
[Mon Jun 15 20:16:36.517537 2026] [security2:error] [pid 51003:tid 51138] [client 82.102.18.118:43638] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/upload/"] [unique_id "ajCyBMpsKyvb75pkSvaIbgAAAZQ"]
[Mon Jun 15 20:16:36.672970 2026] [security2:error] [pid 53359:tid 53609] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/admin/uploads/"] [unique_id "ajCyBPC2Xs1VMQlhsgag3AAAAoY"]
[Mon Jun 15 20:16:36.725757 2026] [security2:error] [pid 53359:tid 53516] [client 162.214.80.21:12506] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.freepik-online.com"] [uri "/media/english/anniversary-wishes/freePiksOnline-1704460229.jpg"] [unique_id "ajCyBPC2Xs1VMQlhsgag3QAAAik"]
[Mon Jun 15 20:16:36.782797 2026] [security2:error] [pid 53359:tid 53585] [client 213.180.203.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyBPC2Xs1VMQlhsgag3gAAAm4"]
[Mon Jun 15 20:16:36.798601 2026] [security2:error] [pid 51003:tid 51183] [client 213.180.203.19:65280] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyBMpsKyvb75pkSvaIgAABwSY"]
[Mon Jun 15 20:16:36.901073 2026] [security2:error] [pid 51003:tid 51140] [client 103.125.146.59:50473] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/goods.php"] [unique_id "ajCyBMpsKyvb75pkSvaIjgAAAZY"]
[Mon Jun 15 20:16:37.100716 2026] [security2:error] [pid 53359:tid 53523] [client 82.102.18.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyBPC2Xs1VMQlhsgag5AAAAjA"]
[Mon Jun 15 20:16:37.100746 2026] [security2:error] [pid 53359:tid 53523] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyBPC2Xs1VMQlhsgag5AAAAjA"]
[Mon Jun 15 20:16:37.115239 2026] [security2:error] [pid 51003:tid 51146] [client 82.102.18.118:43638] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/admin/uploads/"] [unique_id "ajCyBMpsKyvb75pkSvaIigAAAZw"]
[Mon Jun 15 20:16:37.272415 2026] [security2:error] [pid 53359:tid 53547] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/Admin/uploads/"] [unique_id "ajCyBfC2Xs1VMQlhsgag6AAAAkg"]
[Mon Jun 15 20:16:37.433701 2026] [security2:error] [pid 53359:tid 53542] [client 103.125.146.61:24943] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-admin/css/"] [unique_id "ajCyBfC2Xs1VMQlhsgag7AAAAkM"]
[Mon Jun 15 20:16:37.496820 2026] [security2:error] [pid 53359:tid 53622] [client 134.236.18.247:41950] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "www.newyork-gyms.com"] [uri "/wp-comments-post.php"] [unique_id "ajCyBfC2Xs1VMQlhsgag8AAAApM"]
[Mon Jun 15 20:16:37.751349 2026] [security2:error] [pid 51003:tid 51191] [client 82.102.18.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyBcpsKyvb75pkSvaIlgAAAck"]
[Mon Jun 15 20:16:37.751375 2026] [security2:error] [pid 51003:tid 51191] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyBcpsKyvb75pkSvaIlgAAAck"]
[Mon Jun 15 20:16:37.774824 2026] [security2:error] [pid 51003:tid 51247] [client 82.102.18.118:43638] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/Admin/uploads/"] [unique_id "ajCyBcpsKyvb75pkSvaIlAAAAgE"]
[Mon Jun 15 20:16:37.802410 2026] [security2:error] [pid 51003:tid 51167] [client 101.12.86.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kthemani.com"] [uri "/index.php"] [unique_id "ajCyA8psKyvb75pkSvaIZAABsT0"]
[Mon Jun 15 20:16:37.806042 2026] [security2:error] [pid 53359:tid 53555] [client 103.125.146.33:35085] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/"] [unique_id "ajCyBfC2Xs1VMQlhsgag-QAAAlA"]
[Mon Jun 15 20:16:37.850791 2026] [security2:error] [pid 53359:tid 53622] [client 134.236.18.247:41950] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "www.newyork-gyms.com"] [uri "/wp-comments-post.php"] [unique_id "ajCyBfC2Xs1VMQlhsgag8AAAApM"]
[Mon Jun 15 20:16:37.928813 2026] [security2:error] [pid 53359:tid 53604] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/admin/"] [unique_id "ajCyBfC2Xs1VMQlhsgahAwAAAoE"]
[Mon Jun 15 20:16:37.929941 2026] [security2:error] [pid 53359:tid 53409] [remote 142.252.33.74:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.smgl.org"] [uri "/product-category/wholesale-sterling-silver-rings/prong-setting-rings-rings/"] [unique_id "ajCyBfC2Xs1VMQlhsgahAgACbSs"], referer: https://www.bing.org/
[Mon Jun 15 20:16:38.167302 2026] [security2:error] [pid 53359:tid 53613] [client 57.141.14.22:36160] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyBvC2Xs1VMQlhsgahCAACilI"]
[Mon Jun 15 20:16:38.260802 2026] [security2:error] [pid 53359:tid 53502] [client 186.79.170.237:47310] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "store.astonetech.com"] [uri "/pub/index.php"] [unique_id "ajCyBvC2Xs1VMQlhsgahCQAAAhs"]
[Mon Jun 15 20:16:38.287469 2026] [security2:error] [pid 53359:tid 53543] [client 65.111.30.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.procrastinatingworker.imcorp.in"] [uri "/index.php"] [unique_id "ajCyBvC2Xs1VMQlhsgahEAAAAkQ"]
[Mon Jun 15 20:16:38.331052 2026] [security2:error] [pid 53359:tid 53538] [client 103.125.146.67:61229] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/filemanager.php"] [unique_id "ajCyBvC2Xs1VMQlhsgahFQAAAj8"]
[Mon Jun 15 20:16:38.338868 2026] [security2:error] [pid 53359:tid 53424] [remote 35.247.151.219:32790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.151.247.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.cherubicindia.com"] [uri "/wp-login.php"] [unique_id "ajCyBvC2Xs1VMQlhsgahFgACPjo"]
[Mon Jun 15 20:16:38.339112 2026] [security2:error] [pid 53359:tid 53532] [client 82.102.18.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyBvC2Xs1VMQlhsgahDQAAAjk"]
[Mon Jun 15 20:16:38.339127 2026] [security2:error] [pid 53359:tid 53532] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyBvC2Xs1VMQlhsgahDQAAAjk"]
[Mon Jun 15 20:16:38.341922 2026] [security2:error] [pid 51003:tid 51134] [client 82.102.18.118:43638] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/admin/"] [unique_id "ajCyBspsKyvb75pkSvaIsgAAAZA"]
[Mon Jun 15 20:16:38.389528 2026] [security2:error] [pid 53359:tid 53554] [client 5.255.231.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyBvC2Xs1VMQlhsgahFwAAAk8"]
[Mon Jun 15 20:16:38.392924 2026] [security2:error] [pid 53359:tid 53599] [client 5.255.231.53:46204] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyBvC2Xs1VMQlhsgahEQACfGE"]
[Mon Jun 15 20:16:38.429650 2026] [security2:error] [pid 51003:tid 51221] [client 40.77.167.136:57525] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "wantpg.com"] [uri "/public/index.php/in/kanrangana-sikasso-mali-1543751.html"] [unique_id "ajCyBspsKyvb75pkSvaIugAB50g"]
[Mon Jun 15 20:16:38.508266 2026] [security2:error] [pid 53359:tid 53520] [client 149.88.23.79:46828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.23.88.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mizukicnc.com"] [uri "/xmlrpc.php"] [unique_id "ajCyBvC2Xs1VMQlhsgahGQAAAi0"]
[Mon Jun 15 20:16:38.508382 2026] [security2:error] [pid 53359:tid 53520] [client 149.88.23.79:46828] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mizukicnc.com"] [uri "/xmlrpc.php"] [unique_id "ajCyBvC2Xs1VMQlhsgahGQAAAi0"]
[Mon Jun 15 20:16:38.715708 2026] [security2:error] [pid 51003:tid 51161] [client 103.125.146.46:65341] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/plugins/enhanced-text-widget/analyst/src/403.php"] [unique_id "ajCyBspsKyvb75pkSvaIzQAAAas"]
[Mon Jun 15 20:16:38.950834 2026] [security2:error] [pid 51003:tid 51188] [client 82.102.18.118:43638] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-admin/index.php"] [unique_id "ajCyBspsKyvb75pkSvaIvgAAAcY"]
[Mon Jun 15 20:16:39.087695 2026] [security2:error] [pid 51003:tid 51202] [client 103.125.146.71:40161] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/uploads/"] [unique_id "ajCyB8psKyvb75pkSvaI1QAAAdQ"]
[Mon Jun 15 20:16:39.089522 2026] [security2:error] [pid 51003:tid 51197] [client 134.236.18.247:42050] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "www.newyork-gyms.com"] [uri "/wp-comments-post.php"] [unique_id "ajCyB8psKyvb75pkSvaI1AAAAc8"]
[Mon Jun 15 20:16:39.168068 2026] [security2:error] [pid 51003:tid 51116] [remote 89.58.31.106:53652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.31.58.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "foy.lnh.mybluehostin.me"] [uri "/wp-login.php"] [unique_id "ajCyB8psKyvb75pkSvaI2QABwnA"]
[Mon Jun 15 20:16:39.175010 2026] [security2:error] [pid 51003:tid 51154] [client 82.102.18.118:43638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-login.php"] [unique_id "ajCyB8psKyvb75pkSvaI2AAAAaQ"]
[Mon Jun 15 20:16:39.175163 2026] [security2:error] [pid 51003:tid 51154] [client 82.102.18.118:43638] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-login.php"] [unique_id "ajCyB8psKyvb75pkSvaI2AAAAaQ"]
[Mon Jun 15 20:16:39.295253 2026] [security2:error] [pid 53359:tid 53588] [client 57.141.14.98:61856] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyB_C2Xs1VMQlhsgahMwACcQI"]
[Mon Jun 15 20:16:39.329652 2026] [security2:error] [pid 53359:tid 53517] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/images/"] [unique_id "ajCyB_C2Xs1VMQlhsgahNwAAAio"]
[Mon Jun 15 20:16:39.370275 2026] [security2:error] [pid 51003:tid 51101] [remote 89.58.31.106:53652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.31.58.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "foy.lnh.mybluehostin.me"] [uri "/wp-login.php"] [unique_id "ajCyB8psKyvb75pkSvaI5gAB7mE"], referer: https://foy.lnh.mybluehostin.me/wp-login.php
[Mon Jun 15 20:16:39.418237 2026] [security2:error] [pid 51003:tid 51197] [client 134.236.18.247:42050] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "www.newyork-gyms.com"] [uri "/wp-comments-post.php"] [unique_id "ajCyB8psKyvb75pkSvaI1AAAAc8"]
[Mon Jun 15 20:16:39.490471 2026] [security2:error] [pid 53359:tid 53584] [client 103.125.146.59:20047] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/adminfuns.php"] [unique_id "ajCyB_C2Xs1VMQlhsgahPwAAAm0"]
[Mon Jun 15 20:16:39.533176 2026] [security2:error] [pid 51003:tid 51127] [remote 107.174.177.23:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.smgl.org"] [uri "/"] [unique_id "ajCyB8psKyvb75pkSvaI7wAByXs"], referer: https://www.smgl.org/
[Mon Jun 15 20:16:39.570040 2026] [security2:error] [pid 53359:tid 53621] [client 95.108.213.243:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyB_C2Xs1VMQlhsgahQQAAApI"]
[Mon Jun 15 20:16:39.577782 2026] [security2:error] [pid 51003:tid 51183] [client 95.108.213.243:61798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyB8psKyvb75pkSvaI5QABwQA"]
[Mon Jun 15 20:16:39.608423 2026] [autoindex:error] [pid 53359:tid 53366] [remote 52.167.144.177:64344] AH01276: Cannot serve directory /home2/zxsmgcmy/public_html/gurujaskalsi/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:16:39.728151 2026] [security2:error] [pid 51003:tid 51140] [client 31.219.209.201:61856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.209.219.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCyB8psKyvb75pkSvaI8gAAAZY"]
[Mon Jun 15 20:16:39.728286 2026] [security2:error] [pid 51003:tid 51140] [client 31.219.209.201:61856] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCyB8psKyvb75pkSvaI8gAAAZY"]
[Mon Jun 15 20:16:39.915737 2026] [security2:error] [pid 53359:tid 53560] [client 103.125.146.67:39645] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wpx/"] [unique_id "ajCyB_C2Xs1VMQlhsgahTQAAAlU"]
[Mon Jun 15 20:16:39.990207 2026] [security2:error] [pid 53359:tid 53611] [client 213.180.203.187:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyB_C2Xs1VMQlhsgahTgAAAog"]
[Mon Jun 15 20:16:40.013452 2026] [security2:error] [pid 51003:tid 51245] [client 213.180.203.187:39412] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyB8psKyvb75pkSvaI9AAB_2g"]
[Mon Jun 15 20:16:40.039008 2026] [security2:error] [pid 53359:tid 53369] [remote 45.224.97.243:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.smgl.org"] [uri "/product-tag/wholesale/"] [unique_id "ajCyCPC2Xs1VMQlhsgahUQACPwM"]
[Mon Jun 15 20:16:40.094540 2026] [security2:error] [pid 53359:tid 53535] [client 82.102.18.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyB_C2Xs1VMQlhsgahSwAAAjw"]
[Mon Jun 15 20:16:40.094569 2026] [security2:error] [pid 53359:tid 53535] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyB_C2Xs1VMQlhsgahSwAAAjw"]
[Mon Jun 15 20:16:40.227401 2026] [security2:error] [pid 53359:tid 53616] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/images/"] [unique_id "ajCyB_C2Xs1VMQlhsgahSQAAAnk"]
[Mon Jun 15 20:16:40.331342 2026] [security2:error] [pid 53359:tid 53523] [client 103.125.146.61:21177] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/classwithtostring.php"] [unique_id "ajCyCPC2Xs1VMQlhsgahZAAAAjA"]
[Mon Jun 15 20:16:40.390105 2026] [security2:error] [pid 51003:tid 51063] [remote 57.141.14.88:31382] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyCMpsKyvb75pkSvaI-gAB-js"]
[Mon Jun 15 20:16:40.461304 2026] [security2:error] [pid 51003:tid 51258] [client 45.3.40.51:34997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.40.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rajunandkardeputycollector.blog"] [uri "/wp-login.php"] [unique_id "ajCyCMpsKyvb75pkSvaI_QAAAgw"], referer: https://rajunandkardeputycollector.blog/wp-login.php
[Mon Jun 15 20:16:40.474522 2026] [security2:error] [pid 53359:tid 53526] [client 5.255.231.181:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyCPC2Xs1VMQlhsgahZwAAAjM"]
[Mon Jun 15 20:16:40.477062 2026] [security2:error] [pid 53359:tid 53548] [client 5.255.231.181:40002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyCPC2Xs1VMQlhsgahYQACSWA"]
[Mon Jun 15 20:16:40.483348 2026] [security2:error] [pid 53359:tid 53390] [remote 107.174.177.23:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.smgl.org"] [uri "/product-category/wholesale-sterling-silver-rings/prong-setting-rings-rings/"] [unique_id "ajCyCPC2Xs1VMQlhsgahaAACShg"], referer: https://www.smgl.org/
[Mon Jun 15 20:16:40.531299 2026] [security2:error] [pid 53359:tid 53551] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/assets/"] [unique_id "ajCyCPC2Xs1VMQlhsgahawAAAkw"]
[Mon Jun 15 20:16:40.648378 2026] [security2:error] [pid 51003:tid 51207] [client 134.236.18.247:42136] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "www.newyork-gyms.com"] [uri "/wp-comments-post.php"] [unique_id "ajCyCMpsKyvb75pkSvaJAQAAAdk"]
[Mon Jun 15 20:16:40.744571 2026] [security2:error] [pid 53359:tid 53607] [client 103.125.146.57:57563] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/item.php"] [unique_id "ajCyCPC2Xs1VMQlhsgaheQAAAoQ"]
[Mon Jun 15 20:16:40.808922 2026] [security2:error] [pid 53359:tid 53389] [remote 87.250.224.226:0] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.smgl.org"] [uri "/robots.txt"] [unique_id "ajCyCPC2Xs1VMQlhsgahegACKhc"]
[Mon Jun 15 20:16:40.835048 2026] [security2:error] [pid 51003:tid 51232] [client 165.227.135.187:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "rockerzzz.com"] [uri "/index.php"] [unique_id "ajCyCMpsKyvb75pkSvaJCQAAAfI"], referer: http://rockerzzz.com/
[Mon Jun 15 20:16:40.908214 2026] [security2:error] [pid 51003:tid 51171] [client 57.141.14.33:28281] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fifthestate.agency"] [uri "/index.php"] [unique_id "ajCyCMpsKyvb75pkSvaJAwABtSw"]
[Mon Jun 15 20:16:40.946987 2026] [security2:error] [pid 51003:tid 51207] [client 134.236.18.247:42136] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "www.newyork-gyms.com"] [uri "/wp-comments-post.php"] [unique_id "ajCyCMpsKyvb75pkSvaJAQAAAdk"]
[Mon Jun 15 20:16:40.960213 2026] [security2:error] [pid 51003:tid 51153] [client 82.102.18.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyCMpsKyvb75pkSvaJBwAAAaM"]
[Mon Jun 15 20:16:40.960238 2026] [security2:error] [pid 51003:tid 51153] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyCMpsKyvb75pkSvaJBwAAAaM"]
[Mon Jun 15 20:16:41.015722 2026] [security2:error] [pid 53359:tid 53620] [client 65.111.5.42:33575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.5.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rajunandkardeputycollector.blog"] [uri "/wp-login.php"] [unique_id "ajCyCPC2Xs1VMQlhsgahewAAApE"], referer: https://rajunandkardeputycollector.blog/wp-login.php
[Mon Jun 15 20:16:41.029411 2026] [security2:error] [pid 53359:tid 53614] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/assets/"] [unique_id "ajCyCPC2Xs1VMQlhsgahdgAAAos"]
[Mon Jun 15 20:16:41.084033 2026] [security2:error] [pid 51003:tid 51220] [client 5.255.231.72:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyCcpsKyvb75pkSvaJFAAAAeY"]
[Mon Jun 15 20:16:41.147806 2026] [security2:error] [pid 53359:tid 53518] [client 103.125.146.57:51107] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/222.php"] [unique_id "ajCyCfC2Xs1VMQlhsgahfQAAAis"]
[Mon Jun 15 20:16:41.161764 2026] [security2:error] [pid 51003:tid 51196] [client 5.255.231.72:56938] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyCMpsKyvb75pkSvaJCwABznw"]
[Mon Jun 15 20:16:41.233117 2026] [security2:error] [pid 53359:tid 53598] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/"] [unique_id "ajCyCfC2Xs1VMQlhsgahfwAAAns"]
[Mon Jun 15 20:16:41.438598 2026] [security2:error] [pid 51003:tid 51013] [remote 74.7.227.173:37250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.rentswale.ehx.czu.mybluehostin.me"] [uri "/fonts/images/js/images/admin/uploads/source/css/js/subcategory.php"] [unique_id "ajCyCcpsKyvb75pkSvaJJgABkwk"], referer: https://www.rentswale.ehx.czu.mybluehostin.me/fonts/images/js/images/admin/uploads/source/css/js/jquery.min.js
[Mon Jun 15 20:16:41.539750 2026] [security2:error] [pid 51003:tid 51182] [client 104.207.40.216:21891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.40.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rajunandkardeputycollector.blog"] [uri "/wp-login.php"] [unique_id "ajCyCcpsKyvb75pkSvaJKAAAAcA"], referer: https://rajunandkardeputycollector.blog/wp-login.php
[Mon Jun 15 20:16:41.539985 2026] [security2:error] [pid 53359:tid 53564] [client 103.125.146.44:51109] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-admin/"] [unique_id "ajCyCfC2Xs1VMQlhsgahiQAAAlk"]
[Mon Jun 15 20:16:41.556510 2026] [security2:error] [pid 53359:tid 53596] [client 213.180.203.225:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyCfC2Xs1VMQlhsgahiAAAAnk"]
[Mon Jun 15 20:16:41.559567 2026] [security2:error] [pid 51003:tid 51209] [client 213.180.203.225:39136] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyCcpsKyvb75pkSvaJIwAB22U"]
[Mon Jun 15 20:16:41.632532 2026] [security2:error] [pid 53359:tid 53529] [client 82.20.174.92:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kthemani.com"] [uri "/index.php"] [unique_id "ajCyB_C2Xs1VMQlhsgahRwAAAjY"]
[Mon Jun 15 20:16:41.777154 2026] [security2:error] [pid 53359:tid 53536] [client 82.102.18.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyCfC2Xs1VMQlhsgahigAAAj0"]
[Mon Jun 15 20:16:41.777177 2026] [security2:error] [pid 53359:tid 53536] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyCfC2Xs1VMQlhsgahigAAAj0"]
[Mon Jun 15 20:16:41.821431 2026] [security2:error] [pid 53359:tid 53501] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/"] [unique_id "ajCyCfC2Xs1VMQlhsgahhQAAAho"]
[Mon Jun 15 20:16:41.907576 2026] [security2:error] [pid 51003:tid 51014] [remote 68.183.22.192:34620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.22.183.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pacerecruit.com"] [uri "/wp-login.php"] [unique_id "ajCyCcpsKyvb75pkSvaJMgAB_go"]
[Mon Jun 15 20:16:41.975427 2026] [security2:error] [pid 53359:tid 53541] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/upload/image/"] [unique_id "ajCyCfC2Xs1VMQlhsgahjgAAAkI"]
[Mon Jun 15 20:16:42.000146 2026] [security2:error] [pid 53359:tid 53575] [client 87.250.224.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyCfC2Xs1VMQlhsgahjQAAAmQ"]
[Mon Jun 15 20:16:42.001840 2026] [security2:error] [pid 51003:tid 51247] [client 87.250.224.201:49414] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyCcpsKyvb75pkSvaJMwACAQ0"]
[Mon Jun 15 20:16:42.073150 2026] [security2:error] [pid 51003:tid 51019] [remote 68.183.22.192:34620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.22.183.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pacerecruit.com"] [uri "/wp-login.php"] [unique_id "ajCyCspsKyvb75pkSvaJOAAB_Q8"], referer: https://pacerecruit.com/wp-login.php
[Mon Jun 15 20:16:42.182112 2026] [security2:error] [pid 51003:tid 51159] [client 134.236.18.247:42218] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "www.newyork-gyms.com"] [uri "/wp-comments-post.php"] [unique_id "ajCyCspsKyvb75pkSvaJOwAAAak"]
[Mon Jun 15 20:16:42.358333 2026] [security2:error] [pid 53359:tid 53530] [client 57.141.14.37:20856] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyCvC2Xs1VMQlhsgahmwACNyA"]
[Mon Jun 15 20:16:42.441841 2026] [security2:error] [pid 53359:tid 53546] [client 95.108.213.125:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyCvC2Xs1VMQlhsgahoQAAAkc"]
[Mon Jun 15 20:16:42.444837 2026] [security2:error] [pid 53359:tid 53600] [client 95.108.213.125:51188] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyCvC2Xs1VMQlhsgahnwACfQQ"]
[Mon Jun 15 20:16:42.456840 2026] [security2:error] [pid 51003:tid 51242] [client 82.102.18.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyCspsKyvb75pkSvaJPQAAAfw"]
[Mon Jun 15 20:16:42.456868 2026] [security2:error] [pid 51003:tid 51242] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyCspsKyvb75pkSvaJPQAAAfw"]
[Mon Jun 15 20:16:42.477286 2026] [security2:error] [pid 51003:tid 51082] [remote 119.195.102.159:42610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.102.195.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shyenakshainspection.com"] [uri "/wp-login.php"] [unique_id "ajCyCspsKyvb75pkSvaJQgACCk4"]
[Mon Jun 15 20:16:42.490053 2026] [security2:error] [pid 51003:tid 51159] [client 134.236.18.247:42218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "www.newyork-gyms.com"] [uri "/wp-comments-post.php"] [unique_id "ajCyCspsKyvb75pkSvaJOwAAAak"]
[Mon Jun 15 20:16:42.508154 2026] [security2:error] [pid 53359:tid 53592] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/upload/image/"] [unique_id "ajCyCvC2Xs1VMQlhsgahlgAAAnU"]
[Mon Jun 15 20:16:42.673682 2026] [security2:error] [pid 53359:tid 53513] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/assets/images/"] [unique_id "ajCyCvC2Xs1VMQlhsgahpwAAAiY"]
[Mon Jun 15 20:16:42.845393 2026] [security2:error] [pid 53359:tid 53396] [remote 103.127.30.137:35640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.30.127.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rathpoint.com"] [uri "/wp-login.php"] [unique_id "ajCyCvC2Xs1VMQlhsgahqwACax4"]
[Mon Jun 15 20:16:42.921977 2026] [security2:error] [pid 51003:tid 51107] [remote 119.195.102.159:42610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.102.195.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shyenakshainspection.com"] [uri "/wp-login.php"] [unique_id "ajCyCspsKyvb75pkSvaJTAAB32c"], referer: https://shyenakshainspection.com/wp-login.php
[Mon Jun 15 20:16:42.964402 2026] [security2:error] [pid 51003:tid 51195] [client 213.180.203.123:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyCspsKyvb75pkSvaJTQAAAc0"]
[Mon Jun 15 20:16:42.969121 2026] [security2:error] [pid 53359:tid 53505] [client 213.180.203.123:62896] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyCvC2Xs1VMQlhsgahrAACHiE"]
[Mon Jun 15 20:16:43.104746 2026] [security2:error] [pid 53359:tid 53514] [client 82.102.18.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyCvC2Xs1VMQlhsgahrQAAAic"]
[Mon Jun 15 20:16:43.104792 2026] [security2:error] [pid 53359:tid 53514] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyCvC2Xs1VMQlhsgahrQAAAic"]
[Mon Jun 15 20:16:43.108570 2026] [security2:error] [pid 53359:tid 53542] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/assets/images/"] [unique_id "ajCyCvC2Xs1VMQlhsgahqQAAAkM"]
[Mon Jun 15 20:16:43.114873 2026] [security2:error] [pid 53359:tid 53382] [remote 38.70.228.133:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.smgl.org"] [uri "/product-category/wholesale-sterling-silver-rings/prong-setting-rings-rings/"] [unique_id "ajCyC_C2Xs1VMQlhsgahsAACVhA"], referer: https://www.smgl.org/
[Mon Jun 15 20:16:43.265690 2026] [security2:error] [pid 53359:tid 53499] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/Public/"] [unique_id "ajCyC_C2Xs1VMQlhsgahswAAAhg"]
[Mon Jun 15 20:16:43.312740 2026] [security2:error] [pid 53359:tid 53406] [remote 103.127.30.137:35640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.30.127.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rathpoint.com"] [uri "/wp-login.php"] [unique_id "ajCyC_C2Xs1VMQlhsgahtQACPyg"], referer: https://rathpoint.com/wp-login.php
[Mon Jun 15 20:16:43.542609 2026] [security2:error] [pid 53359:tid 53593] [client 87.250.224.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyC_C2Xs1VMQlhsgahvQAAAnY"]
[Mon Jun 15 20:16:43.546112 2026] [security2:error] [pid 51003:tid 51208] [client 87.250.224.112:53238] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyC8psKyvb75pkSvaJWQAB2kI"]
[Mon Jun 15 20:16:43.716233 2026] [security2:error] [pid 53359:tid 53541] [client 82.102.18.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyC_C2Xs1VMQlhsgahvAAAAkI"]
[Mon Jun 15 20:16:43.716255 2026] [security2:error] [pid 53359:tid 53541] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyC_C2Xs1VMQlhsgahvAAAAkI"]
[Mon Jun 15 20:16:43.731178 2026] [security2:error] [pid 53359:tid 53536] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/Public/"] [unique_id "ajCyC_C2Xs1VMQlhsgahuQAAAj0"]
[Mon Jun 15 20:16:43.763795 2026] [security2:error] [pid 53359:tid 53529] [client 134.236.18.247:42286] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "www.newyork-gyms.com"] [uri "/wp-comments-post.php"] [unique_id "ajCyC_C2Xs1VMQlhsgahwAAAAjY"]
[Mon Jun 15 20:16:43.819477 2026] [security2:error] [pid 51003:tid 51085] [remote 57.141.14.84:38402] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fifthestate.agency"] [uri "/index.php"] [unique_id "ajCyC8psKyvb75pkSvaJYAAByFE"]
[Mon Jun 15 20:16:43.884696 2026] [security2:error] [pid 53359:tid 53551] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/vendor/"] [unique_id "ajCyC_C2Xs1VMQlhsgahwwAAAkw"]
[Mon Jun 15 20:16:44.050468 2026] [security2:error] [pid 53359:tid 53529] [client 134.236.18.247:42286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "www.newyork-gyms.com"] [uri "/wp-comments-post.php"] [unique_id "ajCyC_C2Xs1VMQlhsgahwAAAAjY"]
[Mon Jun 15 20:16:44.058234 2026] [security2:error] [pid 53359:tid 53621] [client 95.108.213.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyDPC2Xs1VMQlhsgahyAAAApI"]
[Mon Jun 15 20:16:44.069894 2026] [security2:error] [pid 51003:tid 51204] [client 95.108.213.151:33958] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyC8psKyvb75pkSvaJaAAB1n4"]
[Mon Jun 15 20:16:44.323066 2026] [security2:error] [pid 51003:tid 51212] [client 82.102.18.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyDMpsKyvb75pkSvaJagAAAd4"]
[Mon Jun 15 20:16:44.323089 2026] [security2:error] [pid 51003:tid 51212] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyDMpsKyvb75pkSvaJagAAAd4"]
[Mon Jun 15 20:16:44.325750 2026] [security2:error] [pid 51003:tid 51111] [remote 57.141.14.85:43762] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyDMpsKyvb75pkSvaJbwABy2s"]
[Mon Jun 15 20:16:44.326612 2026] [security2:error] [pid 53359:tid 53571] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/vendor/"] [unique_id "ajCyDPC2Xs1VMQlhsgahyQAAAmA"]
[Mon Jun 15 20:16:44.378948 2026] [rewrite:error] [pid 53359:tid 53607] [client 47.79.197.244:31138] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:16:44.442290 2026] [security2:error] [pid 51003:tid 51246] [client 192.140.64.94:29834] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCyDMpsKyvb75pkSvaJcgAAAgA"]
[Mon Jun 15 20:16:44.442505 2026] [security2:error] [pid 51003:tid 51246] [client 192.140.64.94:29834] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCyDMpsKyvb75pkSvaJcgAAAgA"]
[Mon Jun 15 20:16:44.479705 2026] [security2:error] [pid 53359:tid 53612] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/local/"] [unique_id "ajCyDPC2Xs1VMQlhsgah2gAAAok"]
[Mon Jun 15 20:16:44.535153 2026] [security2:error] [pid 53359:tid 53619] [client 5.255.231.108:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyDPC2Xs1VMQlhsgah3wAAApA"]
[Mon Jun 15 20:16:44.572208 2026] [security2:error] [pid 53359:tid 53600] [client 5.255.231.108:49008] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyDPC2Xs1VMQlhsgah1QACfR8"]
[Mon Jun 15 20:16:44.837138 2026] [rewrite:error] [pid 53359:tid 53567] [client 47.79.197.244:31138] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:16:44.893990 2026] [security2:error] [pid 53359:tid 53535] [client 82.102.18.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyDPC2Xs1VMQlhsgah4QAAAjw"]
[Mon Jun 15 20:16:44.894008 2026] [security2:error] [pid 53359:tid 53535] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyDPC2Xs1VMQlhsgah4QAAAjw"]
[Mon Jun 15 20:16:44.907593 2026] [security2:error] [pid 53359:tid 53421] [remote 172.93.168.48:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.smgl.org"] [uri "/product-category/wholesale-sterling-silver-rings/prong-setting-rings-rings/"] [unique_id "ajCyDPC2Xs1VMQlhsgah6gACgjc"]
[Mon Jun 15 20:16:44.909250 2026] [security2:error] [pid 53359:tid 53509] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/local/"] [unique_id "ajCyDPC2Xs1VMQlhsgah4AAAAiI"]
[Mon Jun 15 20:16:44.991103 2026] [security2:error] [pid 51003:tid 51200] [client 5.255.231.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyDMpsKyvb75pkSvaJfQAAAdI"]
[Mon Jun 15 20:16:45.001635 2026] [security2:error] [pid 53359:tid 53609] [client 5.255.231.36:60768] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyDPC2Xs1VMQlhsgah6AAChh0"]
[Mon Jun 15 20:16:45.046559 2026] [security2:error] [pid 51003:tid 51251] [client 143.244.57.120:45772] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.surveylaya.com"] [uri "/wp-content/plugins/"] [unique_id "ajCyDcpsKyvb75pkSvaJfwAAAgU"]
[Mon Jun 15 20:16:45.062025 2026] [security2:error] [pid 53359:tid 53520] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/modules/"] [unique_id "ajCyDfC2Xs1VMQlhsgah7gAAAi0"]
[Mon Jun 15 20:16:45.313178 2026] [security2:error] [pid 53359:tid 53522] [client 134.236.18.247:42378] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "www.newyork-gyms.com"] [uri "/wp-comments-post.php"] [unique_id "ajCyDfC2Xs1VMQlhsgah9wAAAi8"]
[Mon Jun 15 20:16:45.462860 2026] [security2:error] [pid 53359:tid 53524] [client 209.141.34.188:53520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.34.141.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kvharvestkart.com"] [uri "/wp-login.php"] [unique_id "ajCyDfC2Xs1VMQlhsgah_gAAAjE"]
[Mon Jun 15 20:16:45.487616 2026] [security2:error] [pid 51003:tid 51195] [client 82.102.18.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyDcpsKyvb75pkSvaJhAAAAc0"]
[Mon Jun 15 20:16:45.487644 2026] [security2:error] [pid 51003:tid 51195] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyDcpsKyvb75pkSvaJhAAAAc0"]
[Mon Jun 15 20:16:45.492549 2026] [security2:error] [pid 53359:tid 53588] [client 57.141.14.82:55002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyDfC2Xs1VMQlhsgah-QACcSk"]
[Mon Jun 15 20:16:45.511024 2026] [security2:error] [pid 53359:tid 53601] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/modules/"] [unique_id "ajCyDfC2Xs1VMQlhsgah8QAAAn4"]
[Mon Jun 15 20:16:45.614427 2026] [security2:error] [pid 53359:tid 53522] [client 134.236.18.247:42378] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "www.newyork-gyms.com"] [uri "/wp-comments-post.php"] [unique_id "ajCyDfC2Xs1VMQlhsgah9wAAAi8"]
[Mon Jun 15 20:16:45.646204 2026] [rewrite:error] [pid 51003:tid 51100] [remote 47.79.198.94:25630] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:16:45.670798 2026] [security2:error] [pid 53359:tid 53550] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/Site/"] [unique_id "ajCyDfC2Xs1VMQlhsgaiBwAAAks"]
[Mon Jun 15 20:16:45.671294 2026] [security2:error] [pid 53359:tid 53592] [client 87.250.224.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyDfC2Xs1VMQlhsgaiBgAAAnU"]
[Mon Jun 15 20:16:45.678172 2026] [security2:error] [pid 51003:tid 51148] [client 87.250.224.122:53596] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyDcpsKyvb75pkSvaJkgABnk0"]
[Mon Jun 15 20:16:45.742218 2026] [autoindex:error] [pid 53359:tid 53521] [client 43.153.12.58:0] AH01276: Cannot serve directory /home3/tndnwpmy/public_html/digitalbabjiprasad/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.digitalbabjiprasad.com
[Mon Jun 15 20:16:45.897014 2026] [rewrite:error] [pid 51003:tid 51087] [remote 47.79.198.94:25630] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:16:45.917333 2026] [security2:error] [pid 51003:tid 51041] [remote 57.141.14.73:48730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.14.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wilsonoverseas.com"] [uri "/items/G437035876"] [unique_id "ajCyDcpsKyvb75pkSvaJowAB2CU"]
[Mon Jun 15 20:16:46.112552 2026] [security2:error] [pid 51003:tid 51205] [client 82.102.18.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyDcpsKyvb75pkSvaJoAAAAdc"]
[Mon Jun 15 20:16:46.112576 2026] [security2:error] [pid 51003:tid 51205] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyDcpsKyvb75pkSvaJoAAAAdc"]
[Mon Jun 15 20:16:46.150244 2026] [security2:error] [pid 53359:tid 53543] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/Site/"] [unique_id "ajCyDfC2Xs1VMQlhsgaiDwAAAkQ"]
[Mon Jun 15 20:16:46.288509 2026] [security2:error] [pid 51003:tid 51186] [client 213.180.203.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyDspsKyvb75pkSvaJrwAAAcQ"]
[Mon Jun 15 20:16:46.291050 2026] [security2:error] [pid 51003:tid 51162] [client 213.180.203.19:48474] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyDspsKyvb75pkSvaJqwABrD4"]
[Mon Jun 15 20:16:46.327397 2026] [security2:error] [pid 53359:tid 53539] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/system/"] [unique_id "ajCyDvC2Xs1VMQlhsgaiFQAAAkA"]
[Mon Jun 15 20:16:46.743722 2026] [security2:error] [pid 53359:tid 53579] [client 5.255.231.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyDvC2Xs1VMQlhsgaiHAAAAmg"]
[Mon Jun 15 20:16:46.749190 2026] [security2:error] [pid 53359:tid 53563] [client 5.255.231.53:49320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyDvC2Xs1VMQlhsgaiGgACWEc"]
[Mon Jun 15 20:16:46.818648 2026] [security2:error] [pid 51003:tid 51178] [client 82.102.18.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyDspsKyvb75pkSvaJswAAAbw"]
[Mon Jun 15 20:16:46.818669 2026] [security2:error] [pid 51003:tid 51178] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyDspsKyvb75pkSvaJswAAAbw"]
[Mon Jun 15 20:16:46.825727 2026] [security2:error] [pid 53359:tid 53495] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/system/"] [unique_id "ajCyDvC2Xs1VMQlhsgaiGAAAAhQ"]
[Mon Jun 15 20:16:46.850955 2026] [security2:error] [pid 53359:tid 53516] [client 134.236.18.247:42456] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "www.newyork-gyms.com"] [uri "/wp-comments-post.php"] [unique_id "ajCyDvC2Xs1VMQlhsgaiJgAAAik"]
[Mon Jun 15 20:16:46.853426 2026] [security2:error] [pid 53359:tid 53536] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/wp-content/uploads/"] [unique_id "ajCyDvC2Xs1VMQlhsgaiJwAAAj0"]
[Mon Jun 15 20:16:46.910785 2026] [security2:error] [pid 53359:tid 53507] [client 103.125.146.38:64879] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-admin/js/"] [unique_id "ajCyDvC2Xs1VMQlhsgaiKgAAAiA"]
[Mon Jun 15 20:16:46.980993 2026] [security2:error] [pid 53359:tid 53533] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/template/"] [unique_id "ajCyDvC2Xs1VMQlhsgaiLAAAAjo"]
[Mon Jun 15 20:16:47.136547 2026] [security2:error] [pid 51003:tid 51149] [client 57.141.14.104:37366] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyD8psKyvb75pkSvaJuQABnwQ"]
[Mon Jun 15 20:16:47.156474 2026] [security2:error] [pid 53359:tid 53516] [client 134.236.18.247:42456] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "www.newyork-gyms.com"] [uri "/wp-comments-post.php"] [unique_id "ajCyDvC2Xs1VMQlhsgaiJgAAAik"]
[Mon Jun 15 20:16:47.226995 2026] [security2:error] [pid 51003:tid 51044] [remote 104.250.209.190:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.smgl.org"] [uri "/product-category/wholesale-sterling-silver-rings/prong-setting-rings-rings/"] [unique_id "ajCyD8psKyvb75pkSvaJvwACBSg"]
[Mon Jun 15 20:16:47.326454 2026] [security2:error] [pid 53359:tid 53621] [client 36.73.38.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kthemani.com"] [uri "/index.php"] [unique_id "ajCyDfC2Xs1VMQlhsgah_AACkiI"]
[Mon Jun 15 20:16:47.331385 2026] [security2:error] [pid 53359:tid 53604] [client 103.125.146.33:45815] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/themes/news-portal/zdata.php"] [unique_id "ajCyD_C2Xs1VMQlhsgaiNgAAAoE"]
[Mon Jun 15 20:16:47.431856 2026] [security2:error] [pid 51003:tid 51226] [client 95.108.213.243:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyD8psKyvb75pkSvaJwwAAAew"]
[Mon Jun 15 20:16:47.435099 2026] [security2:error] [pid 53359:tid 53588] [client 95.108.213.243:58800] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyD_C2Xs1VMQlhsgaiNwACcT0"]
[Mon Jun 15 20:16:47.453016 2026] [security2:error] [pid 53359:tid 53577] [client 82.102.18.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyD_C2Xs1VMQlhsgaiNAAAAmY"]
[Mon Jun 15 20:16:47.453041 2026] [security2:error] [pid 53359:tid 53577] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyD_C2Xs1VMQlhsgaiNAAAAmY"]
[Mon Jun 15 20:16:47.460409 2026] [security2:error] [pid 53359:tid 53549] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/template/"] [unique_id "ajCyD_C2Xs1VMQlhsgaiMQAAAko"]
[Mon Jun 15 20:16:47.535868 2026] [autoindex:error] [pid 53359:tid 53560] [client 85.204.70.112:0] AH01276: Cannot serve directory /home4/dreamsta/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:16:47.536342 2026] [security2:error] [pid 53359:tid 53560] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCyD_C2Xs1VMQlhsgaiPwAAAlU"]
[Mon Jun 15 20:16:47.539984 2026] [security2:error] [pid 53359:tid 53591] [client 85.204.70.112:59978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "geekjuggernaut.com"] [uri "/wp-content/uploads/"] [unique_id "ajCyD_C2Xs1VMQlhsgaiOwAAAnQ"]
[Mon Jun 15 20:16:47.632426 2026] [security2:error] [pid 53359:tid 53534] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/shop/"] [unique_id "ajCyD_C2Xs1VMQlhsgaiQwAAAjs"]
[Mon Jun 15 20:16:47.698272 2026] [security2:error] [pid 53359:tid 53558] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/wp-includes/"] [unique_id "ajCyD_C2Xs1VMQlhsgaiRAAAAlM"]
[Mon Jun 15 20:16:47.708050 2026] [security2:error] [pid 51003:tid 51039] [remote 57.141.14.67:27453] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fifthestate.agency"] [uri "/index.php"] [unique_id "ajCyD8psKyvb75pkSvaJyAABoCM"]
[Mon Jun 15 20:16:47.730349 2026] [rewrite:error] [pid 51003:tid 51098] [remote 47.79.197.9:36202] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:16:47.850891 2026] [security2:error] [pid 51003:tid 51252] [client 47.79.206.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "societytodaynews.com"] [uri "/index.php"] [unique_id "ajCyD8psKyvb75pkSvaJzAAAAgY"], referer: https://www.google.com/
[Mon Jun 15 20:16:47.867026 2026] [autoindex:error] [pid 51003:tid 51147] [client 85.204.70.112:0] AH01276: Cannot serve directory /home4/dreamsta/public_html/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:16:47.867513 2026] [security2:error] [pid 51003:tid 51147] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCyD8psKyvb75pkSvaJ1AAAAZ0"]
[Mon Jun 15 20:16:47.870410 2026] [security2:error] [pid 53359:tid 53540] [client 85.204.70.112:59978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "geekjuggernaut.com"] [uri "/wp-includes/"] [unique_id "ajCyD_C2Xs1VMQlhsgaiTQAAAkE"]
[Mon Jun 15 20:16:47.929141 2026] [security2:error] [pid 51003:tid 51160] [client 103.125.146.59:31893] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-config-sample.php"] [unique_id "ajCyD8psKyvb75pkSvaJ1gAAAao"]
[Mon Jun 15 20:16:47.985455 2026] [rewrite:error] [pid 51003:tid 51015] [remote 47.79.197.9:36202] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:16:48.019332 2026] [security2:error] [pid 53359:tid 53563] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/wp-includes/css/"] [unique_id "ajCyEPC2Xs1VMQlhsgaiUwAAAlg"]
[Mon Jun 15 20:16:48.036729 2026] [security2:error] [pid 51003:tid 51137] [client 82.102.18.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyD8psKyvb75pkSvaJ0QAAAZM"]
[Mon Jun 15 20:16:48.036765 2026] [security2:error] [pid 51003:tid 51137] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyD8psKyvb75pkSvaJ0QAAAZM"]
[Mon Jun 15 20:16:48.041557 2026] [security2:error] [pid 53359:tid 53543] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/shop/"] [unique_id "ajCyD_C2Xs1VMQlhsgaiSgAAAkQ"]
[Mon Jun 15 20:16:48.095895 2026] [security2:error] [pid 53359:tid 53449] [remote 47.128.32.80:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mywordsnthoughts.com"] [uri "/top-10-memorable-roles-of-reema-lagoo-the-most-popular-screen-mother-since-1990s/"] [unique_id "ajCyEPC2Xs1VMQlhsgaiVQACaFM"]
[Mon Jun 15 20:16:48.148281 2026] [security2:error] [pid 51003:tid 51146] [client 220.181.108.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "binnyseasyrecipes.com"] [uri "/index.php"] [unique_id "ajCyD8psKyvb75pkSvaJ2gAAAZw"]
[Mon Jun 15 20:16:48.227246 2026] [autoindex:error] [pid 51003:tid 51222] [client 85.204.70.112:0] AH01276: Cannot serve directory /home4/dreamsta/public_html/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:16:48.227721 2026] [security2:error] [pid 51003:tid 51222] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCyEMpsKyvb75pkSvaJ4AAAAeg"]
[Mon Jun 15 20:16:48.229237 2026] [security2:error] [pid 53359:tid 53586] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/files/"] [unique_id "ajCyEPC2Xs1VMQlhsgaiXwAAAm8"]
[Mon Jun 15 20:16:48.246047 2026] [security2:error] [pid 53359:tid 53589] [client 85.204.70.112:59978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "geekjuggernaut.com"] [uri "/wp-includes/css/"] [unique_id "ajCyEPC2Xs1VMQlhsgaiWwAAAnI"]
[Mon Jun 15 20:16:48.317950 2026] [security2:error] [pid 53359:tid 53602] [client 103.125.146.38:52245] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/fm.php"] [unique_id "ajCyEPC2Xs1VMQlhsgaiYwAAAn8"]
[Mon Jun 15 20:16:48.392527 2026] [security2:error] [pid 51003:tid 51168] [client 180.102.110.161:33794] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "spiritedblogger.com"] [uri "/8-international-destinations-to-visit-during-diwali-weekend/"] [unique_id "ajCyEMpsKyvb75pkSvaJ6gAAAbI"]
[Mon Jun 15 20:16:48.392629 2026] [security2:error] [pid 51003:tid 51168] [client 180.102.110.161:33794] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "spiritedblogger.com"] [uri "/8-international-destinations-to-visit-during-diwali-weekend/"] [unique_id "ajCyEMpsKyvb75pkSvaJ6gAAAbI"]
[Mon Jun 15 20:16:48.396561 2026] [security2:error] [pid 51003:tid 51223] [client 134.236.18.247:42526] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "www.newyork-gyms.com"] [uri "/wp-comments-post.php"] [unique_id "ajCyEMpsKyvb75pkSvaJ6wAAAek"]
[Mon Jun 15 20:16:48.528300 2026] [security2:error] [pid 51003:tid 51138] [client 213.180.203.177:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyEMpsKyvb75pkSvaJ7gAAAZQ"]
[Mon Jun 15 20:16:48.531512 2026] [security2:error] [pid 51003:tid 51136] [client 213.180.203.177:56562] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyEMpsKyvb75pkSvaJ7AABkkc"]
[Mon Jun 15 20:16:48.548080 2026] [security2:error] [pid 53359:tid 53601] [client 57.141.14.68:53126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyEPC2Xs1VMQlhsgaiagACflw"]
[Mon Jun 15 20:16:48.587333 2026] [security2:error] [pid 51003:tid 51062] [remote 185.147.140.108:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.smgl.org"] [uri "/product-category/wholesale-sterling-silver-rings/prong-setting-rings-rings/"] [unique_id "ajCyEMpsKyvb75pkSvaJ9gAB0jo"], referer: https://www.smgl.org/
[Mon Jun 15 20:16:48.632388 2026] [security2:error] [pid 53359:tid 53505] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/wp-includes/ID3/"] [unique_id "ajCyEPC2Xs1VMQlhsgaicQAAAh4"]
[Mon Jun 15 20:16:48.660291 2026] [security2:error] [pid 51003:tid 51064] [remote 103.127.30.137:33962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.30.127.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "chemhughesenergy.com"] [uri "/wp-login.php"] [unique_id "ajCyEMpsKyvb75pkSvaJ-AABpzw"]
[Mon Jun 15 20:16:48.700890 2026] [security2:error] [pid 53359:tid 53562] [client 82.102.18.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyEPC2Xs1VMQlhsgaibQAAAlc"]
[Mon Jun 15 20:16:48.700910 2026] [security2:error] [pid 53359:tid 53562] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyEPC2Xs1VMQlhsgaibQAAAlc"]
[Mon Jun 15 20:16:48.701477 2026] [security2:error] [pid 51003:tid 51223] [client 134.236.18.247:42526] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "www.newyork-gyms.com"] [uri "/wp-comments-post.php"] [unique_id "ajCyEMpsKyvb75pkSvaJ6wAAAek"]
[Mon Jun 15 20:16:48.708572 2026] [security2:error] [pid 53359:tid 53497] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/files/"] [unique_id "ajCyEPC2Xs1VMQlhsgaiZwAAAhY"]
[Mon Jun 15 20:16:48.715287 2026] [security2:error] [pid 53359:tid 53537] [client 103.125.146.64:63229] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/speculative8.php"] [unique_id "ajCyEPC2Xs1VMQlhsgaidAAAAj4"]
[Mon Jun 15 20:16:48.838694 2026] [autoindex:error] [pid 53359:tid 53598] [client 85.204.70.112:0] AH01276: Cannot serve directory /home4/dreamsta/public_html/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:16:48.839138 2026] [security2:error] [pid 53359:tid 53598] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCyEPC2Xs1VMQlhsgaieQAAAns"]
[Mon Jun 15 20:16:48.842079 2026] [security2:error] [pid 53359:tid 53518] [client 85.204.70.112:59978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "geekjuggernaut.com"] [uri "/wp-includes/ID3/"] [unique_id "ajCyEPC2Xs1VMQlhsgaidwAAAis"]
[Mon Jun 15 20:16:48.863693 2026] [security2:error] [pid 53359:tid 53496] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/admin/editor/"] [unique_id "ajCyEPC2Xs1VMQlhsgaiegAAAhU"]
[Mon Jun 15 20:16:48.934666 2026] [security2:error] [pid 51003:tid 51102] [remote 91.146.99.41:53796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.99.146.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myexcelguide.com"] [uri "/wp-login.php"] [unique_id "ajCyEMpsKyvb75pkSvaJ_QACBGI"]
[Mon Jun 15 20:16:49.006526 2026] [security2:error] [pid 53359:tid 53567] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/wp-includes/IXR/"] [unique_id "ajCyEfC2Xs1VMQlhsgaifwAAAlw"]
[Mon Jun 15 20:16:49.134582 2026] [security2:error] [pid 53359:tid 53603] [client 103.125.146.43:45455] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-admin/images/admin.php"] [unique_id "ajCyEfC2Xs1VMQlhsgaihQAAAoA"]
[Mon Jun 15 20:16:49.265887 2026] [security2:error] [pid 51003:tid 51014] [remote 91.146.99.41:53796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.99.146.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myexcelguide.com"] [uri "/wp-login.php"] [unique_id "ajCyEcpsKyvb75pkSvaKBQABlgo"], referer: https://myexcelguide.com/wp-login.php
[Mon Jun 15 20:16:49.278480 2026] [security2:error] [pid 51003:tid 51230] [client 82.102.18.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyEcpsKyvb75pkSvaKAgAAAfA"]
[Mon Jun 15 20:16:49.278513 2026] [security2:error] [pid 51003:tid 51230] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyEcpsKyvb75pkSvaKAgAAAfA"]
[Mon Jun 15 20:16:49.288603 2026] [autoindex:error] [pid 53359:tid 53547] [client 85.204.70.112:0] AH01276: Cannot serve directory /home4/dreamsta/public_html/wp-includes/IXR/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:16:49.289071 2026] [security2:error] [pid 53359:tid 53547] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCyEfC2Xs1VMQlhsgaiiwAAAkg"]
[Mon Jun 15 20:16:49.294938 2026] [security2:error] [pid 53359:tid 53495] [client 85.204.70.112:59978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "geekjuggernaut.com"] [uri "/wp-includes/IXR/"] [unique_id "ajCyEfC2Xs1VMQlhsgaiiAAAAhQ"]
[Mon Jun 15 20:16:49.300500 2026] [security2:error] [pid 53359:tid 53563] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/admin/editor/"] [unique_id "ajCyEfC2Xs1VMQlhsgaigQAAAlg"]
[Mon Jun 15 20:16:49.339710 2026] [security2:error] [pid 51003:tid 51120] [remote 103.127.30.137:33962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.30.127.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "chemhughesenergy.com"] [uri "/wp-login.php"] [unique_id "ajCyEcpsKyvb75pkSvaKCQAB43Q"], referer: https://chemhughesenergy.com/wp-login.php
[Mon Jun 15 20:16:49.424129 2026] [security2:error] [pid 53359:tid 53569] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/wp-includes/Requests/"] [unique_id "ajCyEfC2Xs1VMQlhsgaikQAAAl4"]
[Mon Jun 15 20:16:49.454232 2026] [security2:error] [pid 53359:tid 53573] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/include/"] [unique_id "ajCyEfC2Xs1VMQlhsgaikgAAAmI"]
[Mon Jun 15 20:16:49.560898 2026] [security2:error] [pid 53359:tid 53551] [client 103.125.146.36:39767] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/languages/plugins/"] [unique_id "ajCyEfC2Xs1VMQlhsgaikwAAAkw"]
[Mon Jun 15 20:16:49.618570 2026] [autoindex:error] [pid 53359:tid 53533] [client 85.204.70.112:0] AH01276: Cannot serve directory /home4/dreamsta/public_html/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:16:49.619051 2026] [security2:error] [pid 53359:tid 53533] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCyEfC2Xs1VMQlhsgaimQAAAjo"]
[Mon Jun 15 20:16:49.621209 2026] [security2:error] [pid 53359:tid 53602] [client 85.204.70.112:59978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "geekjuggernaut.com"] [uri "/wp-includes/Requests/"] [unique_id "ajCyEfC2Xs1VMQlhsgailgAAAn8"]
[Mon Jun 15 20:16:49.637037 2026] [security2:error] [pid 53359:tid 53554] [client 213.180.203.187:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyEfC2Xs1VMQlhsgaimAAAAk8"]
[Mon Jun 15 20:16:49.638781 2026] [security2:error] [pid 53359:tid 53530] [client 213.180.203.187:42370] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyEfC2Xs1VMQlhsgailAACN1k"]
[Mon Jun 15 20:16:49.795989 2026] [security2:error] [pid 53359:tid 53522] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/wp-includes/SimplePie/"] [unique_id "ajCyEfC2Xs1VMQlhsgaingAAAi8"]
[Mon Jun 15 20:16:49.811201 2026] [rewrite:error] [pid 51003:tid 51086] [remote 47.79.198.221:51668] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:16:49.867254 2026] [security2:error] [pid 53359:tid 53571] [client 82.102.18.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyEfC2Xs1VMQlhsgainAAAAmA"]
[Mon Jun 15 20:16:49.867282 2026] [security2:error] [pid 53359:tid 53571] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyEfC2Xs1VMQlhsgainAAAAmA"]
[Mon Jun 15 20:16:49.871259 2026] [security2:error] [pid 53359:tid 53608] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/include/"] [unique_id "ajCyEfC2Xs1VMQlhsgaimgAAAoU"]
[Mon Jun 15 20:16:49.974537 2026] [autoindex:error] [pid 51003:tid 51249] [client 85.204.70.112:0] AH01276: Cannot serve directory /home4/dreamsta/public_html/wp-includes/SimplePie/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:16:49.975610 2026] [security2:error] [pid 51003:tid 51249] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCyEcpsKyvb75pkSvaKEgAAAgM"]
[Mon Jun 15 20:16:49.978220 2026] [security2:error] [pid 53359:tid 53588] [client 85.204.70.112:59978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "geekjuggernaut.com"] [uri "/wp-includes/SimplePie/"] [unique_id "ajCyEfC2Xs1VMQlhsgaioQAAAnE"]
[Mon Jun 15 20:16:50.016524 2026] [security2:error] [pid 51003:tid 51175] [client 103.125.146.67:65479] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/uploads/admin.php"] [unique_id "ajCyEspsKyvb75pkSvaKFgAAAbk"]
[Mon Jun 15 20:16:50.027844 2026] [security2:error] [pid 53359:tid 53537] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/Assets/"] [unique_id "ajCyEvC2Xs1VMQlhsgaiqgAAAj4"]
[Mon Jun 15 20:16:50.063578 2026] [rewrite:error] [pid 51003:tid 51104] [remote 47.79.198.221:51668] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:16:50.120245 2026] [security2:error] [pid 53359:tid 53598] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/wp-includes/Text/"] [unique_id "ajCyEvC2Xs1VMQlhsgairQAAAns"]
[Mon Jun 15 20:16:50.186764 2026] [security2:error] [pid 53359:tid 53594] [client 31.219.209.201:62459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.209.219.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCyEvC2Xs1VMQlhsgaisgAAAnc"]
[Mon Jun 15 20:16:50.186875 2026] [security2:error] [pid 53359:tid 53594] [client 31.219.209.201:62459] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCyEvC2Xs1VMQlhsgaisgAAAnc"]
[Mon Jun 15 20:16:50.188810 2026] [security2:error] [pid 53359:tid 53409] [remote 104.239.99.123:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.smgl.org"] [uri "/product-category/wholesale-sterling-silver-rings/prong-setting-rings-rings/"] [unique_id "ajCyEvC2Xs1VMQlhsgaisQACdCs"], referer: https://www.smgl.org/
[Mon Jun 15 20:16:50.249475 2026] [security2:error] [pid 53359:tid 53582] [client 65.111.30.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.procrastinatingworker.imcorp.in"] [uri "/index.php"] [unique_id "ajCyEvC2Xs1VMQlhsgairAAAAms"]
[Mon Jun 15 20:16:50.352683 2026] [autoindex:error] [pid 51003:tid 51168] [client 85.204.70.112:0] AH01276: Cannot serve directory /home4/dreamsta/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:16:50.353195 2026] [security2:error] [pid 51003:tid 51168] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCyEspsKyvb75pkSvaKIgAAAbI"]
[Mon Jun 15 20:16:50.390317 2026] [security2:error] [pid 53359:tid 53502] [client 85.204.70.112:59978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "geekjuggernaut.com"] [uri "/wp-includes/Text/"] [unique_id "ajCyEvC2Xs1VMQlhsgaitgAAAhs"]
[Mon Jun 15 20:16:50.416390 2026] [security2:error] [pid 53359:tid 53457] [remote 57.141.14.103:40020] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyEvC2Xs1VMQlhsgaitQACQFs"]
[Mon Jun 15 20:16:50.436510 2026] [security2:error] [pid 53359:tid 53584] [client 103.125.146.42:29249] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/404.php"] [unique_id "ajCyEvC2Xs1VMQlhsgaiugAAAm0"]
[Mon Jun 15 20:16:50.467454 2026] [security2:error] [pid 51003:tid 51258] [client 82.102.18.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyEspsKyvb75pkSvaKHgAAAgw"]
[Mon Jun 15 20:16:50.467486 2026] [security2:error] [pid 51003:tid 51258] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyEspsKyvb75pkSvaKHgAAAgw"]
[Mon Jun 15 20:16:50.475033 2026] [security2:error] [pid 53359:tid 53611] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/Assets/"] [unique_id "ajCyEvC2Xs1VMQlhsgairwAAAog"]
[Mon Jun 15 20:16:50.524420 2026] [security2:error] [pid 53359:tid 53547] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/wp-content/mu-plugins-old/"] [unique_id "ajCyEvC2Xs1VMQlhsgaivAAAAkg"]
[Mon Jun 15 20:16:50.630457 2026] [security2:error] [pid 53359:tid 53580] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/images/stories/"] [unique_id "ajCyEvC2Xs1VMQlhsgaiwwAAAmk"]
[Mon Jun 15 20:16:50.764953 2026] [security2:error] [pid 53359:tid 53581] [client 5.255.231.181:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyEvC2Xs1VMQlhsgaixgAAAmo"]
[Mon Jun 15 20:16:50.795999 2026] [security2:error] [pid 53359:tid 53603] [client 5.255.231.181:52096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyEvC2Xs1VMQlhsgaiwQACgFE"]
[Mon Jun 15 20:16:50.835940 2026] [security2:error] [pid 51003:tid 51223] [client 103.125.146.34:39383] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/about.php"] [unique_id "ajCyEspsKyvb75pkSvaKKwAAAek"]
[Mon Jun 15 20:16:51.054452 2026] [security2:error] [pid 51003:tid 51157] [client 82.102.18.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyEspsKyvb75pkSvaKKgAAAac"]
[Mon Jun 15 20:16:51.054481 2026] [security2:error] [pid 51003:tid 51157] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyEspsKyvb75pkSvaKKgAAAac"]
[Mon Jun 15 20:16:51.062869 2026] [security2:error] [pid 53359:tid 53515] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/images/stories/"] [unique_id "ajCyEvC2Xs1VMQlhsgaiyAAAAig"]
[Mon Jun 15 20:16:51.100761 2026] [security2:error] [pid 51003:tid 51031] [remote 74.7.242.56:54612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.242.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.softhubtechno.ehx.czu.mybluehostin.me"] [uri "/images/img/Admin/logo/images/testimonials/js/img/images/clients/contact.php"] [unique_id "ajCyE8psKyvb75pkSvaKMAAB0Rs"], referer: https://www.softhubtechno.ehx.czu.mybluehostin.me/images/img/Admin/logo/images/testimonials/js/img/images/clients/3.png
[Mon Jun 15 20:16:51.205690 2026] [security2:error] [pid 53359:tid 53615] [client 103.125.146.46:40873] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/file.php"] [unique_id "ajCyE_C2Xs1VMQlhsgai1wAAAow"]
[Mon Jun 15 20:16:51.229789 2026] [security2:error] [pid 53359:tid 53508] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/plugins/"] [unique_id "ajCyE_C2Xs1VMQlhsgai2AAAAiE"]
[Mon Jun 15 20:16:51.265305 2026] [security2:error] [pid 53359:tid 53511] [client 157.55.39.6:63867] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ybsolutions.in"] [uri "/index.php"] [unique_id "ajCyE_C2Xs1VMQlhsgai2QACJDY"]
[Mon Jun 15 20:16:51.366073 2026] [security2:error] [pid 51003:tid 51178] [client 143.244.57.88:39428] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "rkfreshmart.net"] [uri "/wp-content/plugins/"] [unique_id "ajCyE8psKyvb75pkSvaKMgAAAbw"]
[Mon Jun 15 20:16:51.617459 2026] [security2:error] [pid 51003:tid 51142] [client 103.125.146.73:54341] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/themes/news-portal/sitebar.php"] [unique_id "ajCyE8psKyvb75pkSvaKOwAAAZg"]
[Mon Jun 15 20:16:51.622726 2026] [security2:error] [pid 53359:tid 53598] [client 57.141.14.62:20620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyE_C2Xs1VMQlhsgai5AACe0w"]
[Mon Jun 15 20:16:51.661050 2026] [security2:error] [pid 53359:tid 53557] [client 82.102.18.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyE_C2Xs1VMQlhsgai3gAAAlI"]
[Mon Jun 15 20:16:51.661073 2026] [security2:error] [pid 53359:tid 53557] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyE_C2Xs1VMQlhsgai3gAAAlI"]
[Mon Jun 15 20:16:51.671352 2026] [security2:error] [pid 53359:tid 53588] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/plugins/"] [unique_id "ajCyE_C2Xs1VMQlhsgai2wAAAnE"]
[Mon Jun 15 20:16:51.780148 2026] [security2:error] [pid 53359:tid 53612] [client 188.66.247.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kthemani.com"] [uri "/index.php"] [unique_id "ajCyEfC2Xs1VMQlhsgaioAAAAok"]
[Mon Jun 15 20:16:51.829696 2026] [security2:error] [pid 53359:tid 53596] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/php/"] [unique_id "ajCyE_C2Xs1VMQlhsgai7QAAAnk"]
[Mon Jun 15 20:16:51.927884 2026] [security2:error] [pid 53359:tid 53605] [client 157.55.39.6:63867] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ybsolutions.in"] [uri "/index.php"] [unique_id "ajCyE_C2Xs1VMQlhsgai8AACgjU"]
[Mon Jun 15 20:16:51.975122 2026] [security2:error] [pid 53359:tid 53543] [client 5.255.231.72:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyE_C2Xs1VMQlhsgai8wAAAkQ"]
[Mon Jun 15 20:16:51.977744 2026] [security2:error] [pid 53359:tid 53621] [client 5.255.231.72:36094] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyE_C2Xs1VMQlhsgai7gACklY"]
[Mon Jun 15 20:16:52.012902 2026] [security2:error] [pid 51003:tid 51175] [client 103.125.146.52:53001] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/updates.php"] [unique_id "ajCyFMpsKyvb75pkSvaKRgAAAbk"]
[Mon Jun 15 20:16:52.029777 2026] [security2:error] [pid 53359:tid 53579] [client 65.111.30.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.procrastinatingworker.imcorp.in"] [uri "/index.php"] [unique_id "ajCyE_C2Xs1VMQlhsgai9AAAAmg"]
[Mon Jun 15 20:16:52.040785 2026] [security2:error] [pid 53359:tid 53512] [client 85.204.70.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyEvC2Xs1VMQlhsgaiygAAAiU"]
[Mon Jun 15 20:16:52.040806 2026] [security2:error] [pid 53359:tid 53512] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyEvC2Xs1VMQlhsgaiygAAAiU"]
[Mon Jun 15 20:16:52.102773 2026] [security2:error] [pid 53359:tid 53477] [remote 57.141.14.17:61944] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fifthestate.agency"] [uri "/index.php"] [unique_id "ajCyE_C2Xs1VMQlhsgai7wACUG8"]
[Mon Jun 15 20:16:52.143807 2026] [security2:error] [pid 53359:tid 53564] [client 85.204.70.112:59978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/wp-content/mu-plugins-old/"] [unique_id "ajCyEvC2Xs1VMQlhsgaixAAAAlk"]
[Mon Jun 15 20:16:52.388981 2026] [security2:error] [pid 51003:tid 51239] [client 103.125.146.33:42579] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/themes/fukasawa/inc/classes/403.php"] [unique_id "ajCyFMpsKyvb75pkSvaKSgAAAfk"]
[Mon Jun 15 20:16:52.395120 2026] [security2:error] [pid 53359:tid 53526] [client 82.102.18.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyFPC2Xs1VMQlhsgai_AAAAjM"]
[Mon Jun 15 20:16:52.395139 2026] [security2:error] [pid 53359:tid 53526] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyFPC2Xs1VMQlhsgai_AAAAjM"]
[Mon Jun 15 20:16:52.402431 2026] [security2:error] [pid 53359:tid 53590] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/php/"] [unique_id "ajCyFPC2Xs1VMQlhsgai-QAAAnM"]
[Mon Jun 15 20:16:52.430297 2026] [security2:error] [pid 53359:tid 53577] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/wp-content/themes/classic/inc/"] [unique_id "ajCyFPC2Xs1VMQlhsgajAAAAAmY"]
[Mon Jun 15 20:16:52.557460 2026] [security2:error] [pid 53359:tid 53618] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-admin/css/"] [unique_id "ajCyFPC2Xs1VMQlhsgajAgAAAo8"]
[Mon Jun 15 20:16:52.573841 2026] [security2:error] [pid 53359:tid 53481] [remote 107.181.158.18:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.smgl.org"] [uri "/product-category/wholesale-sterling-silver-rings/prong-setting-rings-rings/"] [unique_id "ajCyFPC2Xs1VMQlhsgajAwACjHM"], referer: http://www.baidu.org/
[Mon Jun 15 20:16:52.655946 2026] [security2:error] [pid 53359:tid 53508] [client 213.180.203.225:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyFPC2Xs1VMQlhsgajCgAAAiE"]
[Mon Jun 15 20:16:52.658769 2026] [security2:error] [pid 53359:tid 53561] [client 213.180.203.225:50470] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyFPC2Xs1VMQlhsgajBAACVns"]
[Mon Jun 15 20:16:52.709072 2026] [security2:error] [pid 53359:tid 53505] [client 85.204.70.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyFPC2Xs1VMQlhsgajCwAAAh4"]
[Mon Jun 15 20:16:52.709093 2026] [security2:error] [pid 53359:tid 53505] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyFPC2Xs1VMQlhsgajCwAAAh4"]
[Mon Jun 15 20:16:52.713044 2026] [security2:error] [pid 53359:tid 53571] [client 85.204.70.112:59978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/wp-content/themes/classic/inc/"] [unique_id "ajCyFPC2Xs1VMQlhsgajBQAAAmA"]
[Mon Jun 15 20:16:52.771216 2026] [autoindex:error] [pid 53359:tid 53514] [client 82.102.18.118:47714] AH01276: Cannot serve directory /home3/itjbthmy/public_html/jcpenneysurvey1/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:16:52.771688 2026] [security2:error] [pid 53359:tid 53514] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-admin/css/"] [unique_id "ajCyFPC2Xs1VMQlhsgajDgAAAic"]
[Mon Jun 15 20:16:52.790056 2026] [security2:error] [pid 53359:tid 53560] [client 103.125.146.45:54873] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/plugins/hello-plus/classes/ehp-sarang.php"] [unique_id "ajCyFPC2Xs1VMQlhsgajDwAAAlU"]
[Mon Jun 15 20:16:52.842869 2026] [security2:error] [pid 53359:tid 53591] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/wp-content/plugins/ninja-forms/"] [unique_id "ajCyFPC2Xs1VMQlhsgajEQAAAnQ"]
[Mon Jun 15 20:16:52.962621 2026] [security2:error] [pid 53359:tid 53537] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-content/themes/twentytwenty/"] [unique_id "ajCyFPC2Xs1VMQlhsgajEgAAAj4"]
[Mon Jun 15 20:16:53.105709 2026] [security2:error] [pid 53359:tid 53540] [client 85.204.70.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyFfC2Xs1VMQlhsgajFQAAAkE"]
[Mon Jun 15 20:16:53.105736 2026] [security2:error] [pid 53359:tid 53540] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyFfC2Xs1VMQlhsgajFQAAAkE"]
[Mon Jun 15 20:16:53.109683 2026] [security2:error] [pid 53359:tid 53588] [client 85.204.70.112:59978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/wp-content/plugins/ninja-forms/"] [unique_id "ajCyFPC2Xs1VMQlhsgajEwAAAnE"]
[Mon Jun 15 20:16:53.171061 2026] [security2:error] [pid 53359:tid 53548] [client 143.14.151.206:48896] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.azrconsulting.in"] [uri "/index.php"] [unique_id "ajCyEvC2Xs1VMQlhsgaixwAAAkk"], referer: https://www.azrconsulting.in/
[Mon Jun 15 20:16:53.212926 2026] [security2:error] [pid 51003:tid 51161] [client 103.125.146.32:59793] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-admin/css/colors/blue/"] [unique_id "ajCyFcpsKyvb75pkSvaKYAAAAas"]
[Mon Jun 15 20:16:53.240502 2026] [security2:error] [pid 53359:tid 53621] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/wp-content/mu-plugins/"] [unique_id "ajCyFfC2Xs1VMQlhsgajIQAAApI"]
[Mon Jun 15 20:16:53.251544 2026] [security2:error] [pid 51003:tid 51198] [client 87.250.224.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyFcpsKyvb75pkSvaKXwAAAdA"]
[Mon Jun 15 20:16:53.255165 2026] [security2:error] [pid 53359:tid 53600] [client 87.250.224.201:57670] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyFfC2Xs1VMQlhsgajHgACfXw"]
[Mon Jun 15 20:16:53.288059 2026] [security2:error] [pid 53359:tid 53502] [client 57.141.14.76:32941] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyFfC2Xs1VMQlhsgajGQACGwM"]
[Mon Jun 15 20:16:53.379711 2026] [security2:error] [pid 51003:tid 51245] [client 47.79.207.167:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "societytodaynews.com"] [uri "/index.php"] [unique_id "ajCyFcpsKyvb75pkSvaKWgAAAf8"], referer: https://www.google.com/
[Mon Jun 15 20:16:53.405877 2026] [security2:error] [pid 53359:tid 53593] [client 82.102.18.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyFfC2Xs1VMQlhsgajHQAAAnY"]
[Mon Jun 15 20:16:53.405899 2026] [security2:error] [pid 53359:tid 53593] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyFfC2Xs1VMQlhsgajHQAAAnY"]
[Mon Jun 15 20:16:53.414013 2026] [security2:error] [pid 53359:tid 53596] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-content/themes/twentytwenty/"] [unique_id "ajCyFfC2Xs1VMQlhsgajGAAAAnk"]
[Mon Jun 15 20:16:53.447888 2026] [autoindex:error] [pid 53359:tid 53544] [client 85.204.70.112:0] AH01276: Cannot serve directory /home4/dreamsta/public_html/wp-content/mu-plugins/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:16:53.448363 2026] [security2:error] [pid 53359:tid 53544] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCyFfC2Xs1VMQlhsgajJwAAAkU"]
[Mon Jun 15 20:16:53.452229 2026] [security2:error] [pid 53359:tid 53532] [client 85.204.70.112:59978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "geekjuggernaut.com"] [uri "/wp-content/mu-plugins/"] [unique_id "ajCyFfC2Xs1VMQlhsgajJgAAAjk"]
[Mon Jun 15 20:16:53.569981 2026] [security2:error] [pid 53359:tid 53603] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-content/cache/"] [unique_id "ajCyFfC2Xs1VMQlhsgajLQAAAoA"]
[Mon Jun 15 20:16:53.597957 2026] [security2:error] [pid 51003:tid 51191] [client 103.125.146.79:38473] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/plugins/"] [unique_id "ajCyFcpsKyvb75pkSvaKZwAAAck"]
[Mon Jun 15 20:16:53.658131 2026] [security2:error] [pid 53359:tid 53570] [client 95.108.213.125:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyFfC2Xs1VMQlhsgajMgAAAl8"]
[Mon Jun 15 20:16:53.660769 2026] [security2:error] [pid 51003:tid 51199] [client 95.108.213.125:34296] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyFcpsKyvb75pkSvaKZgAB0XU"]
[Mon Jun 15 20:16:53.700454 2026] [security2:error] [pid 53359:tid 53590] [client 213.180.203.123:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyFfC2Xs1VMQlhsgajNgAAAnM"]
[Mon Jun 15 20:16:53.724547 2026] [security2:error] [pid 53359:tid 53529] [client 57.141.14.19:27652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyFfC2Xs1VMQlhsgajMQACNhM"]
[Mon Jun 15 20:16:53.735042 2026] [security2:error] [pid 53359:tid 53567] [client 213.180.203.123:61398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyFfC2Xs1VMQlhsgajNAACXDw"]
[Mon Jun 15 20:16:53.806275 2026] [security2:error] [pid 53359:tid 53556] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/wp-includes/Text/Diff/Renderer/"] [unique_id "ajCyFfC2Xs1VMQlhsgajPQAAAlE"]
[Mon Jun 15 20:16:53.821458 2026] [autoindex:error] [pid 53359:tid 53592] [client 82.102.18.118:0] AH01276: Cannot serve directory /home3/itjbthmy/public_html/jcpenneysurvey1/wp-content/cache/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:16:53.821899 2026] [security2:error] [pid 53359:tid 53592] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCyFfC2Xs1VMQlhsgajPgAAAnU"]
[Mon Jun 15 20:16:53.826289 2026] [security2:error] [pid 53359:tid 53552] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-content/cache/"] [unique_id "ajCyFfC2Xs1VMQlhsgajOAAAAk0"]
[Mon Jun 15 20:16:54.026043 2026] [security2:error] [pid 53359:tid 53606] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-admin/maint/"] [unique_id "ajCyFvC2Xs1VMQlhsgajRgAAAoM"]
[Mon Jun 15 20:16:54.049575 2026] [security2:error] [pid 53359:tid 53498] [client 103.125.146.61:46857] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/1.php"] [unique_id "ajCyFvC2Xs1VMQlhsgajRwAAAhc"]
[Mon Jun 15 20:16:54.063911 2026] [autoindex:error] [pid 53359:tid 53582] [client 85.204.70.112:0] AH01276: Cannot serve directory /home4/dreamsta/public_html/wp-includes/Text/Diff/Renderer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:16:54.064388 2026] [security2:error] [pid 53359:tid 53582] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCyFvC2Xs1VMQlhsgajSAAAAms"]
[Mon Jun 15 20:16:54.069654 2026] [security2:error] [pid 53359:tid 53591] [client 85.204.70.112:59978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "geekjuggernaut.com"] [uri "/wp-includes/Text/Diff/Renderer/"] [unique_id "ajCyFfC2Xs1VMQlhsgajRAAAAnQ"]
[Mon Jun 15 20:16:54.225606 2026] [security2:error] [pid 53359:tid 53579] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/wp-includes/blocks/"] [unique_id "ajCyFvC2Xs1VMQlhsgajUAAAAmg"]
[Mon Jun 15 20:16:54.273050 2026] [autoindex:error] [pid 53359:tid 53605] [client 82.102.18.118:47714] AH01276: Cannot serve directory /home3/itjbthmy/public_html/jcpenneysurvey1/wp-admin/maint/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:16:54.273613 2026] [security2:error] [pid 53359:tid 53605] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-admin/maint/"] [unique_id "ajCyFvC2Xs1VMQlhsgajTAAAAoI"]
[Mon Jun 15 20:16:54.294175 2026] [security2:error] [pid 53359:tid 53512] [client 141.11.62.23:42190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sarthakpotdar.com"] [uri "/.env"] [unique_id "ajCyFvC2Xs1VMQlhsgajUgAAAiU"]
[Mon Jun 15 20:16:54.305053 2026] [security2:error] [pid 51003:tid 51142] [client 87.250.224.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyFspsKyvb75pkSvaKbgAAAZg"]
[Mon Jun 15 20:16:54.308810 2026] [security2:error] [pid 53359:tid 53519] [client 87.250.224.112:52630] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyFvC2Xs1VMQlhsgajTQACLGA"]
[Mon Jun 15 20:16:54.436215 2026] [security2:error] [pid 53359:tid 53585] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-content/plugins/akismet/"] [unique_id "ajCyFvC2Xs1VMQlhsgajWgAAAm4"]
[Mon Jun 15 20:16:54.450434 2026] [security2:error] [pid 53359:tid 53580] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "geekjuggernaut.com"] [uri "/wp-includes/blocks/index.php"] [unique_id "ajCyFvC2Xs1VMQlhsgajWwAAAmk"]
[Mon Jun 15 20:16:54.452257 2026] [security2:error] [pid 53359:tid 53608] [client 85.204.70.112:59978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "geekjuggernaut.com"] [uri "/wp-includes/blocks/"] [unique_id "ajCyFvC2Xs1VMQlhsgajVQAAAoU"]
[Mon Jun 15 20:16:54.531932 2026] [security2:error] [pid 51003:tid 51189] [client 103.125.146.48:53959] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-json/wp/v2/posts"] [unique_id "ajCyFspsKyvb75pkSvaKeQAAAcc"]
[Mon Jun 15 20:16:54.617772 2026] [security2:error] [pid 53359:tid 53495] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/wp-includes/certificates/"] [unique_id "ajCyFvC2Xs1VMQlhsgajYAAAAhQ"]
[Mon Jun 15 20:16:54.656719 2026] [security2:error] [pid 53359:tid 53381] [remote 103.28.36.168:46714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.36.28.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "desk-magnet.com"] [uri "/wp-login.php"] [unique_id "ajCyFvC2Xs1VMQlhsgajYwACkg8"]
[Mon Jun 15 20:16:54.754722 2026] [security2:error] [pid 51003:tid 51200] [client 95.108.213.136:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyFspsKyvb75pkSvaKggAAAdI"]
[Mon Jun 15 20:16:54.760441 2026] [security2:error] [pid 53359:tid 53527] [client 95.108.213.136:53420] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyFvC2Xs1VMQlhsgajXwACNAg"]
[Mon Jun 15 20:16:54.768462 2026] [security2:error] [pid 53359:tid 53570] [client 213.180.203.244:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyFvC2Xs1VMQlhsgajawAAAl8"]
[Mon Jun 15 20:16:54.806383 2026] [security2:error] [pid 51003:tid 51133] [client 213.180.203.244:38250] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyFspsKyvb75pkSvaKfgABj2A"]
[Mon Jun 15 20:16:54.878747 2026] [security2:error] [pid 51003:tid 51164] [client 192.140.64.94:29804] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCyFspsKyvb75pkSvaKhgAAAa4"]
[Mon Jun 15 20:16:54.883811 2026] [security2:error] [pid 51003:tid 51164] [client 192.140.64.94:29804] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCyFspsKyvb75pkSvaKhgAAAa4"]
[Mon Jun 15 20:16:54.891990 2026] [autoindex:error] [pid 53359:tid 53508] [client 85.204.70.112:0] AH01276: Cannot serve directory /home4/dreamsta/public_html/wp-includes/certificates/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:16:54.892543 2026] [security2:error] [pid 53359:tid 53508] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCyFvC2Xs1VMQlhsgajcQAAAiE"]
[Mon Jun 15 20:16:54.895360 2026] [security2:error] [pid 53359:tid 53529] [client 85.204.70.112:59978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "geekjuggernaut.com"] [uri "/wp-includes/certificates/"] [unique_id "ajCyFvC2Xs1VMQlhsgajbgAAAjY"]
[Mon Jun 15 20:16:54.930894 2026] [security2:error] [pid 51003:tid 51176] [client 82.102.18.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyFspsKyvb75pkSvaKgQAAAbo"]
[Mon Jun 15 20:16:54.930921 2026] [security2:error] [pid 51003:tid 51176] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyFspsKyvb75pkSvaKgQAAAbo"]
[Mon Jun 15 20:16:54.940223 2026] [security2:error] [pid 53359:tid 53520] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-content/plugins/akismet/"] [unique_id "ajCyFvC2Xs1VMQlhsgajYQAAAi0"]
[Mon Jun 15 20:16:54.969070 2026] [security2:error] [pid 51003:tid 51028] [remote 84.46.84.90:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.smgl.org"] [uri "/"] [unique_id "ajCyFspsKyvb75pkSvaKhwAB_hg"]
[Mon Jun 15 20:16:55.028989 2026] [security2:error] [pid 53359:tid 53542] [client 152.59.170.10:54742] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ahk.kavadevelopers.com"] [uri "/public/index.php"] [unique_id "ajCyFvC2Xs1VMQlhsgajTwACQxg"], referer: https://ahk.kavadevelopers.com/public/admin/jobwork/create
[Mon Jun 15 20:16:55.037587 2026] [security2:error] [pid 53359:tid 53552] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/wp-includes/customize/"] [unique_id "ajCyF_C2Xs1VMQlhsgajdgAAAk0"]
[Mon Jun 15 20:16:55.110859 2026] [security2:error] [pid 53359:tid 53386] [remote 103.28.36.168:46714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.36.28.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "desk-magnet.com"] [uri "/wp-login.php"] [unique_id "ajCyF_C2Xs1VMQlhsgajdwACMRQ"], referer: https://desk-magnet.com/wp-login.php
[Mon Jun 15 20:16:55.127749 2026] [security2:error] [pid 53359:tid 53573] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-includes/assets/"] [unique_id "ajCyF_C2Xs1VMQlhsgajeQAAAmI"]
[Mon Jun 15 20:16:55.225739 2026] [security2:error] [pid 51003:tid 51152] [client 213.180.203.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyF8psKyvb75pkSvaKjgAAAaI"]
[Mon Jun 15 20:16:55.227911 2026] [security2:error] [pid 53359:tid 53599] [client 213.180.203.5:58766] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyF_C2Xs1VMQlhsgajeAACfF8"]
[Mon Jun 15 20:16:55.239570 2026] [autoindex:error] [pid 53359:tid 53506] [client 85.204.70.112:0] AH01276: Cannot serve directory /home4/dreamsta/public_html/wp-includes/customize/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:16:55.240217 2026] [security2:error] [pid 53359:tid 53506] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCyF_C2Xs1VMQlhsgajggAAAh8"]
[Mon Jun 15 20:16:55.240899 2026] [lsapi:error] [pid 51003:tid 51045] [remote 182.253.124.138:0] [host www.kthemani.com] Error on sending request(GET /en/products/3095593/ HTTP/2.0); uri(/index.php) content-length(0): ReceiveAckHdr: nothing to read from backend (LVE ID 1402; user ID 1402), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html
[Mon Jun 15 20:16:55.250372 2026] [security2:error] [pid 51003:tid 51216] [client 213.180.203.155:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyF8psKyvb75pkSvaKkAAAAeI"]
[Mon Jun 15 20:16:55.261429 2026] [security2:error] [pid 53359:tid 53560] [client 85.204.70.112:59978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "geekjuggernaut.com"] [uri "/wp-includes/customize/"] [unique_id "ajCyF_C2Xs1VMQlhsgajfgAAAlU"]
[Mon Jun 15 20:16:55.275709 2026] [security2:error] [pid 53359:tid 53568] [client 213.180.203.155:51840] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyF_C2Xs1VMQlhsgajegACXT4"]
[Mon Jun 15 20:16:55.365078 2026] [autoindex:error] [pid 53359:tid 53512] [client 82.102.18.118:0] AH01276: Cannot serve directory /home3/itjbthmy/public_html/jcpenneysurvey1/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:16:55.365585 2026] [security2:error] [pid 53359:tid 53512] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCyF_C2Xs1VMQlhsgajiQAAAiU"]
[Mon Jun 15 20:16:55.369776 2026] [security2:error] [pid 53359:tid 53504] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-includes/assets/"] [unique_id "ajCyF_C2Xs1VMQlhsgajhgAAAh0"]
[Mon Jun 15 20:16:55.383505 2026] [security2:error] [pid 51003:tid 51087] [remote 57.141.14.108:35197] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fifthestate.agency"] [uri "/index.php"] [unique_id "ajCyF8psKyvb75pkSvaKjQABs1M"]
[Mon Jun 15 20:16:55.398148 2026] [security2:error] [pid 53359:tid 53393] [remote 74.7.227.178:41830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "softhubtechno.ehx.czu.mybluehostin.me"] [uri "/images/js/js/images/clients/Admin/logo/img/carrer.php"] [unique_id "ajCyF_C2Xs1VMQlhsgajigACaBs"], referer: https://softhubtechno.ehx.czu.mybluehostin.me/images/js/js/images/clients/Admin/logo/img/logo.png
[Mon Jun 15 20:16:55.429359 2026] [security2:error] [pid 53359:tid 53574] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/wp-includes/fonts/"] [unique_id "ajCyF_C2Xs1VMQlhsgajjAAAAmM"]
[Mon Jun 15 20:16:55.544563 2026] [security2:error] [pid 53359:tid 53536] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-includes/block-patterns/"] [unique_id "ajCyF_C2Xs1VMQlhsgajjgAAAj0"]
[Mon Jun 15 20:16:55.700002 2026] [autoindex:error] [pid 53359:tid 53554] [client 85.204.70.112:0] AH01276: Cannot serve directory /home4/dreamsta/public_html/wp-includes/fonts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:16:55.700496 2026] [security2:error] [pid 53359:tid 53554] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCyF_C2Xs1VMQlhsgajkgAAAk8"]
[Mon Jun 15 20:16:55.710452 2026] [security2:error] [pid 53359:tid 53603] [client 85.204.70.112:59978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "geekjuggernaut.com"] [uri "/wp-includes/fonts/"] [unique_id "ajCyF_C2Xs1VMQlhsgajjwAAAoA"]
[Mon Jun 15 20:16:55.723689 2026] [security2:error] [pid 53359:tid 53383] [remote 139.59.150.41:54540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.150.59.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sriramsidd.com"] [uri "/wp-login.php"] [unique_id "ajCyF_C2Xs1VMQlhsgajkwAChBE"]
[Mon Jun 15 20:16:55.747649 2026] [security2:error] [pid 51003:tid 51069] [remote 84.46.84.90:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.smgl.org"] [uri "/product-category/wholesale-sterling-silver-rings/prong-setting-rings-rings/"] [unique_id "ajCyF8psKyvb75pkSvaKmgABp0E"], referer: https://www.smgl.org/
[Mon Jun 15 20:16:55.816069 2026] [autoindex:error] [pid 51003:tid 51250] [client 82.102.18.118:0] AH01276: Cannot serve directory /home3/itjbthmy/public_html/jcpenneysurvey1/wp-includes/block-patterns/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:16:55.817022 2026] [security2:error] [pid 51003:tid 51250] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCyF8psKyvb75pkSvaKmwAAAgQ"]
[Mon Jun 15 20:16:55.819843 2026] [security2:error] [pid 53359:tid 53616] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-includes/block-patterns/"] [unique_id "ajCyF_C2Xs1VMQlhsgajlQAAAo0"]
[Mon Jun 15 20:16:55.853509 2026] [security2:error] [pid 53359:tid 53617] [client 5.255.231.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyF_C2Xs1VMQlhsgajmAAAAo4"]
[Mon Jun 15 20:16:55.859424 2026] [security2:error] [pid 51003:tid 51146] [client 5.255.231.51:55670] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyF8psKyvb75pkSvaKmAABnC4"]
[Mon Jun 15 20:16:55.898298 2026] [security2:error] [pid 53359:tid 53615] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/wp-includes/images/"] [unique_id "ajCyF_C2Xs1VMQlhsgajmgAAAow"]
[Mon Jun 15 20:16:55.949673 2026] [security2:error] [pid 53359:tid 53546] [client 57.141.14.101:27650] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyF_C2Xs1VMQlhsgajmQACRwQ"]
[Mon Jun 15 20:16:56.035686 2026] [security2:error] [pid 53359:tid 53520] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-includes/block-supports/"] [unique_id "ajCyGPC2Xs1VMQlhsgajoAAAAi0"]
[Mon Jun 15 20:16:56.082835 2026] [autoindex:error] [pid 53359:tid 53542] [client 85.204.70.112:0] AH01276: Cannot serve directory /home4/dreamsta/public_html/wp-includes/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:16:56.083368 2026] [security2:error] [pid 53359:tid 53542] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCyGPC2Xs1VMQlhsgajpAAAAkM"]
[Mon Jun 15 20:16:56.087017 2026] [security2:error] [pid 53359:tid 53522] [client 85.204.70.112:59978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "geekjuggernaut.com"] [uri "/wp-includes/images/"] [unique_id "ajCyGPC2Xs1VMQlhsgajnwAAAi8"]
[Mon Jun 15 20:16:56.243799 2026] [security2:error] [pid 53359:tid 53598] [client 95.108.213.212:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyGPC2Xs1VMQlhsgajpgAAAns"]
[Mon Jun 15 20:16:56.247167 2026] [autoindex:error] [pid 51003:tid 51230] [client 85.204.70.112:0] AH01276: Cannot serve directory /home4/dreamsta/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:16:56.247644 2026] [security2:error] [pid 51003:tid 51230] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCyGMpsKyvb75pkSvaKpgAAAfA"]
[Mon Jun 15 20:16:56.250595 2026] [security2:error] [pid 53359:tid 53511] [client 95.108.213.212:60444] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyGPC2Xs1VMQlhsgajpQACJB4"]
[Mon Jun 15 20:16:56.253536 2026] [security2:error] [pid 53359:tid 53556] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "geekjuggernaut.com"] [uri "/.well-known/"] [unique_id "ajCyGPC2Xs1VMQlhsgajpwAAAlE"]
[Mon Jun 15 20:16:56.275017 2026] [autoindex:error] [pid 51003:tid 51233] [client 82.102.18.118:0] AH01276: Cannot serve directory /home3/itjbthmy/public_html/jcpenneysurvey1/wp-includes/block-supports/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:16:56.275512 2026] [security2:error] [pid 51003:tid 51233] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCyGMpsKyvb75pkSvaKpwAAAfM"]
[Mon Jun 15 20:16:56.322064 2026] [security2:error] [pid 53359:tid 53517] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-includes/block-supports/"] [unique_id "ajCyGPC2Xs1VMQlhsgajqAAAAio"]
[Mon Jun 15 20:16:56.417623 2026] [security2:error] [pid 53359:tid 53506] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/ALFA_DATA/"] [unique_id "ajCyGPC2Xs1VMQlhsgajrQAAAh8"]
[Mon Jun 15 20:16:56.479005 2026] [security2:error] [pid 53359:tid 53501] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-includes/html-api/"] [unique_id "ajCyGPC2Xs1VMQlhsgajrwAAAho"]
[Mon Jun 15 20:16:56.521389 2026] [security2:error] [pid 51003:tid 51044] [remote 213.171.208.62:40470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.208.171.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "extrovertevents.com"] [uri "/wp-login.php"] [unique_id "ajCyGMpsKyvb75pkSvaKsAABuCg"]
[Mon Jun 15 20:16:56.644814 2026] [security2:error] [pid 51003:tid 51005] [remote 2a03:2880:f806:48:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ruchini.hemani.finance"] [uri "/index.php"] [unique_id "ajCyGMpsKyvb75pkSvaKrwAB3AE"]
[Mon Jun 15 20:16:56.669975 2026] [autoindex:error] [pid 51003:tid 51190] [client 82.102.18.118:0] AH01276: Cannot serve directory /home3/itjbthmy/public_html/jcpenneysurvey1/wp-includes/html-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:16:56.670531 2026] [security2:error] [pid 51003:tid 51190] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCyGMpsKyvb75pkSvaKtwAAAcg"]
[Mon Jun 15 20:16:56.677430 2026] [security2:error] [pid 53359:tid 53514] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-includes/html-api/"] [unique_id "ajCyGPC2Xs1VMQlhsgajugAAAic"]
[Mon Jun 15 20:16:56.707828 2026] [security2:error] [pid 51003:tid 51248] [client 85.204.70.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyGMpsKyvb75pkSvaKtQAAAgI"]
[Mon Jun 15 20:16:56.707854 2026] [security2:error] [pid 51003:tid 51248] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyGMpsKyvb75pkSvaKtQAAAgI"]
[Mon Jun 15 20:16:56.709690 2026] [security2:error] [pid 53359:tid 53579] [client 85.204.70.112:59978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/ALFA_DATA/"] [unique_id "ajCyGPC2Xs1VMQlhsgajtwAAAmg"]
[Mon Jun 15 20:16:56.740231 2026] [security2:error] [pid 51003:tid 51077] [remote 213.171.208.62:40470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.208.171.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "extrovertevents.com"] [uri "/wp-login.php"] [unique_id "ajCyGMpsKyvb75pkSvaKugABnUk"], referer: https://extrovertevents.com/wp-login.php
[Mon Jun 15 20:16:56.839493 2026] [security2:error] [pid 53359:tid 53621] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/.well-knownold/"] [unique_id "ajCyGPC2Xs1VMQlhsgajwQAAApI"]
[Mon Jun 15 20:16:56.852209 2026] [security2:error] [pid 51003:tid 51133] [client 66.249.66.45:36421] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "wantpg.com"] [uri "/public/index.php/in/alu-shahdeo-punjab-pakistan-1867383.html"] [unique_id "ajCyGMpsKyvb75pkSvaKwwAAAY8"]
[Mon Jun 15 20:16:57.054769 2026] [security2:error] [pid 53359:tid 53539] [client 52.167.144.211:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCyGPC2Xs1VMQlhsgajtAACQCg"]
[Mon Jun 15 20:16:57.119225 2026] [security2:error] [pid 51003:tid 51252] [client 99.245.166.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sciencecenterrajkot.org"] [uri "/index.php"] [unique_id "ajCyGMpsKyvb75pkSvaKsgAAAgY"]
[Mon Jun 15 20:16:57.124431 2026] [security2:error] [pid 53359:tid 53615] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-includes/js/"] [unique_id "ajCyGfC2Xs1VMQlhsgajzAAAAow"]
[Mon Jun 15 20:16:57.155763 2026] [security2:error] [pid 51003:tid 51144] [client 85.204.70.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyGcpsKyvb75pkSvaKygAAAZo"]
[Mon Jun 15 20:16:57.155788 2026] [security2:error] [pid 51003:tid 51144] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyGcpsKyvb75pkSvaKygAAAZo"]
[Mon Jun 15 20:16:57.169028 2026] [security2:error] [pid 53359:tid 53590] [client 85.204.70.112:59978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/.well-knownold/"] [unique_id "ajCyGPC2Xs1VMQlhsgajxwAAAnM"]
[Mon Jun 15 20:16:57.176673 2026] [security2:error] [pid 53359:tid 53564] [client 104.210.140.128:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kunashni.org"] [uri "/index.php"] [unique_id "ajCyF_C2Xs1VMQlhsgajnQACWSY"]
[Mon Jun 15 20:16:57.265038 2026] [security2:error] [pid 53359:tid 53558] [client 95.108.213.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyGfC2Xs1VMQlhsgaj0wAAAlM"]
[Mon Jun 15 20:16:57.270006 2026] [security2:error] [pid 53359:tid 53550] [client 95.108.213.143:33382] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyGfC2Xs1VMQlhsgajzgACS3Y"]
[Mon Jun 15 20:16:57.347810 2026] [security2:error] [pid 53359:tid 53480] [remote 103.74.176.102:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.smgl.org"] [uri "/product-category/wholesale-sterling-silver-rings/prong-setting-rings-rings/"] [unique_id "ajCyGfC2Xs1VMQlhsgaj2gACgnI"], referer: https://www.smgl.org/
[Mon Jun 15 20:16:57.349045 2026] [autoindex:error] [pid 51003:tid 51136] [client 85.204.70.112:0] AH01276: Cannot serve directory /home4/dreamsta/public_html/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:16:57.349475 2026] [security2:error] [pid 51003:tid 51136] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCyGcpsKyvb75pkSvaK0AAAAZI"]
[Mon Jun 15 20:16:57.352510 2026] [security2:error] [pid 53359:tid 53555] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "geekjuggernaut.com"] [uri "/.well-known/acme-challenge/"] [unique_id "ajCyGfC2Xs1VMQlhsgaj2QAAAlA"]
[Mon Jun 15 20:16:57.355255 2026] [autoindex:error] [pid 51003:tid 51157] [client 82.102.18.118:0] AH01276: Cannot serve directory /home3/itjbthmy/public_html/jcpenneysurvey1/wp-includes/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:16:57.356396 2026] [security2:error] [pid 51003:tid 51157] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCyGcpsKyvb75pkSvaK0QAAAac"]
[Mon Jun 15 20:16:57.392766 2026] [security2:error] [pid 53359:tid 53613] [client 57.141.14.112:27820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyGfC2Xs1VMQlhsgaj1QACimo"]
[Mon Jun 15 20:16:57.418345 2026] [security2:error] [pid 53359:tid 53524] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-includes/js/"] [unique_id "ajCyGfC2Xs1VMQlhsgaj1AAAAjE"]
[Mon Jun 15 20:16:57.502838 2026] [security2:error] [pid 53359:tid 53599] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/cgi-bin/"] [unique_id "ajCyGfC2Xs1VMQlhsgaj3wAAAnw"]
[Mon Jun 15 20:16:57.571110 2026] [security2:error] [pid 53359:tid 53553] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-includes/php-compat/"] [unique_id "ajCyGfC2Xs1VMQlhsgaj4AAAAk4"]
[Mon Jun 15 20:16:57.680664 2026] [cgid:error] [pid 51003:tid 51201] [client 85.204.70.112:0] AH01265: stderr from /home4/dreamsta/public_html/cgi-bin/: attempt to invoke directory as script
[Mon Jun 15 20:16:57.681210 2026] [security2:error] [pid 51003:tid 51201] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCyGcpsKyvb75pkSvaK1gAAAdM"]
[Mon Jun 15 20:16:57.689660 2026] [security2:error] [pid 53359:tid 53504] [client 85.204.70.112:59978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "geekjuggernaut.com"] [uri "/cgi-bin/"] [unique_id "ajCyGfC2Xs1VMQlhsgaj4wAAAh0"]
[Mon Jun 15 20:16:57.704148 2026] [security2:error] [pid 53359:tid 53523] [client 213.180.203.103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyGfC2Xs1VMQlhsgaj6AAAAjA"]
[Mon Jun 15 20:16:57.713995 2026] [security2:error] [pid 51003:tid 51213] [client 213.180.203.250:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyGcpsKyvb75pkSvaK2AAAAd8"]
[Mon Jun 15 20:16:57.715332 2026] [security2:error] [pid 53359:tid 53511] [client 213.180.203.103:34752] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyGfC2Xs1VMQlhsgaj4QACJCw"]
[Mon Jun 15 20:16:57.727419 2026] [security2:error] [pid 53359:tid 53600] [client 213.180.203.250:54454] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyGfC2Xs1VMQlhsgaj4gACfWw"]
[Mon Jun 15 20:16:57.791068 2026] [autoindex:error] [pid 53359:tid 53586] [client 82.102.18.118:0] AH01276: Cannot serve directory /home3/itjbthmy/public_html/jcpenneysurvey1/wp-includes/php-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:16:57.791563 2026] [security2:error] [pid 53359:tid 53586] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCyGfC2Xs1VMQlhsgaj7gAAAm8"]
[Mon Jun 15 20:16:57.796185 2026] [security2:error] [pid 53359:tid 53526] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-includes/php-compat/"] [unique_id "ajCyGfC2Xs1VMQlhsgaj6wAAAjM"]
[Mon Jun 15 20:16:57.823098 2026] [security2:error] [pid 53359:tid 53512] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/index/"] [unique_id "ajCyGfC2Xs1VMQlhsgaj8wAAAiU"]
[Mon Jun 15 20:16:57.970439 2026] [security2:error] [pid 53359:tid 53620] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-includes/PHPMailer/"] [unique_id "ajCyGfC2Xs1VMQlhsgaj-gAAApE"]
[Mon Jun 15 20:16:58.100673 2026] [security2:error] [pid 53359:tid 53528] [client 85.204.70.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyGvC2Xs1VMQlhsgakAQAAAjU"]
[Mon Jun 15 20:16:58.100698 2026] [security2:error] [pid 53359:tid 53528] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyGvC2Xs1VMQlhsgakAQAAAjU"]
[Mon Jun 15 20:16:58.121961 2026] [security2:error] [pid 53359:tid 53609] [client 85.204.70.112:59978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index/"] [unique_id "ajCyGfC2Xs1VMQlhsgaj_QAAAoY"]
[Mon Jun 15 20:16:58.177688 2026] [autoindex:error] [pid 51003:tid 51158] [client 82.102.18.118:0] AH01276: Cannot serve directory /home3/itjbthmy/public_html/jcpenneysurvey1/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:16:58.178274 2026] [security2:error] [pid 51003:tid 51158] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCyGspsKyvb75pkSvaK4QAAAag"]
[Mon Jun 15 20:16:58.180848 2026] [security2:error] [pid 53359:tid 53617] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-includes/PHPMailer/"] [unique_id "ajCyGvC2Xs1VMQlhsgakAgAAAo4"]
[Mon Jun 15 20:16:58.272521 2026] [security2:error] [pid 53359:tid 53432] [remote 119.195.102.159:55442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.102.195.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cleantech-holdings.us"] [uri "/wp-login.php"] [unique_id "ajCyGvC2Xs1VMQlhsgakBAACbEI"]
[Mon Jun 15 20:16:58.301176 2026] [security2:error] [pid 53359:tid 53517] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/id/"] [unique_id "ajCyGvC2Xs1VMQlhsgakBgAAAio"]
[Mon Jun 15 20:16:58.307006 2026] [security2:error] [pid 51003:tid 51232] [client 5.255.231.114:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyGspsKyvb75pkSvaK6gAAAfI"]
[Mon Jun 15 20:16:58.308892 2026] [security2:error] [pid 53359:tid 53613] [client 5.255.231.114:61740] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyGvC2Xs1VMQlhsgakAwACikM"]
[Mon Jun 15 20:16:58.356183 2026] [security2:error] [pid 53359:tid 53588] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-includes/pomo/"] [unique_id "ajCyGvC2Xs1VMQlhsgakCQAAAnE"]
[Mon Jun 15 20:16:58.545318 2026] [security2:error] [pid 53359:tid 53548] [client 85.204.70.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyGvC2Xs1VMQlhsgakEAAAAkk"]
[Mon Jun 15 20:16:58.545360 2026] [security2:error] [pid 53359:tid 53548] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyGvC2Xs1VMQlhsgakEAAAAkk"]
[Mon Jun 15 20:16:58.548436 2026] [security2:error] [pid 53359:tid 53549] [client 85.204.70.112:59978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/id/"] [unique_id "ajCyGvC2Xs1VMQlhsgakDgAAAko"]
[Mon Jun 15 20:16:58.567520 2026] [autoindex:error] [pid 53359:tid 53611] [client 82.102.18.118:0] AH01276: Cannot serve directory /home3/itjbthmy/public_html/jcpenneysurvey1/wp-includes/pomo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:16:58.568088 2026] [security2:error] [pid 53359:tid 53611] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCyGvC2Xs1VMQlhsgakFAAAAog"]
[Mon Jun 15 20:16:58.616262 2026] [security2:error] [pid 53359:tid 53574] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-includes/pomo/"] [unique_id "ajCyGvC2Xs1VMQlhsgakEwAAAmM"]
[Mon Jun 15 20:16:58.699766 2026] [security2:error] [pid 53359:tid 53581] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/www/"] [unique_id "ajCyGvC2Xs1VMQlhsgakFgAAAmo"]
[Mon Jun 15 20:16:58.768762 2026] [security2:error] [pid 53359:tid 53579] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-includes/random_compat/"] [unique_id "ajCyGvC2Xs1VMQlhsgakGQAAAmg"]
[Mon Jun 15 20:16:58.771402 2026] [security2:error] [pid 53359:tid 53430] [remote 119.195.102.159:55442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.102.195.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cleantech-holdings.us"] [uri "/wp-login.php"] [unique_id "ajCyGvC2Xs1VMQlhsgakGAACdEA"], referer: https://cleantech-holdings.us/wp-login.php
[Mon Jun 15 20:16:58.803802 2026] [security2:error] [pid 51003:tid 51217] [client 95.108.213.209:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyGspsKyvb75pkSvaK_AAAAeM"]
[Mon Jun 15 20:16:58.806629 2026] [security2:error] [pid 53359:tid 53599] [client 95.108.213.209:64912] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyGvC2Xs1VMQlhsgakFQACfEs"]
[Mon Jun 15 20:16:58.835618 2026] [security2:error] [pid 53359:tid 53435] [remote 167.160.48.177:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.smgl.org"] [uri "/product-category/wholesale-sterling-silver-rings/prong-setting-rings-rings/"] [unique_id "ajCyGvC2Xs1VMQlhsgakHAAChUU"]
[Mon Jun 15 20:16:58.838907 2026] [security2:error] [pid 53359:tid 53519] [client 57.141.14.51:58756] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyGvC2Xs1VMQlhsgakFwACLDA"]
[Mon Jun 15 20:16:58.936603 2026] [security2:error] [pid 53359:tid 53580] [client 85.204.70.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyGvC2Xs1VMQlhsgakHwAAAmk"]
[Mon Jun 15 20:16:58.936629 2026] [security2:error] [pid 53359:tid 53580] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyGvC2Xs1VMQlhsgakHwAAAmk"]
[Mon Jun 15 20:16:58.940271 2026] [security2:error] [pid 53359:tid 53585] [client 85.204.70.112:59978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/www/"] [unique_id "ajCyGvC2Xs1VMQlhsgakGwAAAm4"]
[Mon Jun 15 20:16:59.037653 2026] [security2:error] [pid 51003:tid 51084] [remote 185.191.171.1:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "7artfashion.com"] [uri "/product-tag/lavender/"] [unique_id "ajCyG8psKyvb75pkSvaLBQAB5VA"]
[Mon Jun 15 20:16:59.037866 2026] [security2:error] [pid 51003:tid 51219] [client 185.191.171.1:0] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "7artfashion.com"] [uri "/product-tag/lavender/"] [unique_id "ajCyG8psKyvb75pkSvaLBQAB5VA"]
[Mon Jun 15 20:16:59.097016 2026] [security2:error] [pid 53359:tid 53564] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/web/"] [unique_id "ajCyG_C2Xs1VMQlhsgakKQAAAlk"]
[Mon Jun 15 20:16:59.139667 2026] [security2:error] [pid 53359:tid 53373] [remote 74.7.227.161:43162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.shreeramsweets.co.in"] [uri "/plugins/lightgallery/js/plugins/lightgallery/js/images_scroller/images/blog/grid/images_scroller/plugins/owl-carousel/css/images/hampers-gift.php"] [unique_id "ajCyG_C2Xs1VMQlhsgakLQACgAc"], referer: https://www.shreeramsweets.co.in/plugins/lightgallery/js/plugins/lightgallery/js/images_scroller/images/blog/grid/images_scroller/plugins/owl-carousel/css/images/restaurant.jpg
[Mon Jun 15 20:16:59.229950 2026] [security2:error] [pid 53359:tid 53594] [client 82.102.18.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyGvC2Xs1VMQlhsgakKAAAAnc"]
[Mon Jun 15 20:16:59.229975 2026] [security2:error] [pid 53359:tid 53594] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyGvC2Xs1VMQlhsgakKAAAAnc"]
[Mon Jun 15 20:16:59.233473 2026] [security2:error] [pid 53359:tid 53615] [client 87.250.224.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyG_C2Xs1VMQlhsgakMgAAAow"]
[Mon Jun 15 20:16:59.245827 2026] [security2:error] [pid 53359:tid 53604] [client 87.250.224.34:43548] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyG_C2Xs1VMQlhsgakLAACgT0"]
[Mon Jun 15 20:16:59.250380 2026] [security2:error] [pid 53359:tid 53512] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-includes/random_compat/"] [unique_id "ajCyGvC2Xs1VMQlhsgakJgAAAiU"]
[Mon Jun 15 20:16:59.326772 2026] [security2:error] [pid 53359:tid 53607] [client 85.204.70.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyG_C2Xs1VMQlhsgakNgAAAoQ"]
[Mon Jun 15 20:16:59.326889 2026] [security2:error] [pid 53359:tid 53607] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyG_C2Xs1VMQlhsgakNgAAAoQ"]
[Mon Jun 15 20:16:59.328499 2026] [security2:error] [pid 53359:tid 53530] [client 85.204.70.112:59978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/web/"] [unique_id "ajCyG_C2Xs1VMQlhsgakMwAAAjc"]
[Mon Jun 15 20:16:59.431344 2026] [security2:error] [pid 53359:tid 53602] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-includes/rest-api/"] [unique_id "ajCyG_C2Xs1VMQlhsgakQgAAAn8"]
[Mon Jun 15 20:16:59.499297 2026] [security2:error] [pid 53359:tid 53518] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/uploads/"] [unique_id "ajCyG_C2Xs1VMQlhsgakRgAAAis"]
[Mon Jun 15 20:16:59.552403 2026] [security2:error] [pid 53359:tid 53548] [client 65.111.30.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.procrastinatingworker.imcorp.in"] [uri "/index.php"] [unique_id "ajCyG_C2Xs1VMQlhsgakRAAAAkk"]
[Mon Jun 15 20:16:59.565000 2026] [security2:error] [pid 53359:tid 53619] [client 138.122.48.161:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kthemani.com"] [uri "/index.php"] [unique_id "ajCyGfC2Xs1VMQlhsgaj5wACkDc"]
[Mon Jun 15 20:16:59.624727 2026] [autoindex:error] [pid 51003:tid 51172] [client 82.102.18.118:0] AH01276: Cannot serve directory /home3/itjbthmy/public_html/jcpenneysurvey1/wp-includes/rest-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:16:59.625857 2026] [security2:error] [pid 51003:tid 51172] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCyG8psKyvb75pkSvaLEgAAAbY"]
[Mon Jun 15 20:16:59.627641 2026] [security2:error] [pid 53359:tid 53514] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-includes/rest-api/"] [unique_id "ajCyG_C2Xs1VMQlhsgakRwAAAic"]
[Mon Jun 15 20:16:59.740379 2026] [security2:error] [pid 51003:tid 51204] [client 85.204.70.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyG8psKyvb75pkSvaLFQAAAdY"]
[Mon Jun 15 20:16:59.740410 2026] [security2:error] [pid 51003:tid 51204] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyG8psKyvb75pkSvaLFQAAAdY"]
[Mon Jun 15 20:16:59.751098 2026] [security2:error] [pid 53359:tid 53591] [client 85.204.70.112:59978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/uploads/"] [unique_id "ajCyG_C2Xs1VMQlhsgakSwAAAnQ"]
[Mon Jun 15 20:16:59.774411 2026] [security2:error] [pid 51003:tid 51177] [client 52.167.144.173:3954] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ybsolutions.in"] [uri "/index.php"] [unique_id "ajCyG8psKyvb75pkSvaLGQABuw8"]
[Mon Jun 15 20:16:59.782770 2026] [security2:error] [pid 53359:tid 53621] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-includes/sitemaps/"] [unique_id "ajCyG_C2Xs1VMQlhsgakUwAAApI"]
[Mon Jun 15 20:16:59.787083 2026] [security2:error] [pid 51003:tid 51205] [client 95.108.213.192:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyG8psKyvb75pkSvaLGAAAAdc"]
[Mon Jun 15 20:16:59.789815 2026] [security2:error] [pid 53359:tid 53596] [client 95.108.213.192:50154] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyG_C2Xs1VMQlhsgakTQACeVM"]
[Mon Jun 15 20:16:59.929600 2026] [security2:error] [pid 53359:tid 53541] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/upload/"] [unique_id "ajCyG_C2Xs1VMQlhsgakVgAAAkI"]
[Mon Jun 15 20:16:59.933838 2026] [security2:error] [pid 53359:tid 53608] [client 57.141.14.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aarohiarts.org"] [uri "/index.php"] [unique_id "ajCyG_C2Xs1VMQlhsgakUgAAAoU"]
[Mon Jun 15 20:17:00.017360 2026] [security2:error] [pid 51003:tid 51222] [client 103.125.146.52:55349] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/themes/twentytwentyone/content-index.php"] [unique_id "ajCyHMpsKyvb75pkSvaLJAAAAeg"]
[Mon Jun 15 20:17:00.020364 2026] [security2:error] [pid 51003:tid 51231] [client 57.141.14.49:32397] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rohandasgupta.com"] [uri "/index.php"] [unique_id "ajCyG8psKyvb75pkSvaLHAAB8VI"]
[Mon Jun 15 20:17:00.033987 2026] [autoindex:error] [pid 51003:tid 51145] [client 82.102.18.118:0] AH01276: Cannot serve directory /home3/itjbthmy/public_html/jcpenneysurvey1/wp-includes/sitemaps/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:17:00.034547 2026] [security2:error] [pid 51003:tid 51145] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCyHMpsKyvb75pkSvaLJQAAAZs"]
[Mon Jun 15 20:17:00.038030 2026] [security2:error] [pid 53359:tid 53595] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-includes/sitemaps/"] [unique_id "ajCyG_C2Xs1VMQlhsgakVwAAAng"]
[Mon Jun 15 20:17:00.104435 2026] [security2:error] [pid 51003:tid 51221] [client 57.141.14.3:36524] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyG8psKyvb75pkSvaLIQAB52Q"]
[Mon Jun 15 20:17:00.225302 2026] [security2:error] [pid 51003:tid 51208] [client 85.204.70.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyHMpsKyvb75pkSvaLKAAAAdo"]
[Mon Jun 15 20:17:00.225345 2026] [security2:error] [pid 51003:tid 51208] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyHMpsKyvb75pkSvaLKAAAAdo"]
[Mon Jun 15 20:17:00.232511 2026] [security2:error] [pid 53359:tid 53528] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-includes/sodium_compat/"] [unique_id "ajCyHPC2Xs1VMQlhsgakYQAAAjU"]
[Mon Jun 15 20:17:00.242129 2026] [security2:error] [pid 53359:tid 53507] [client 85.204.70.112:59978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/upload/"] [unique_id "ajCyHPC2Xs1VMQlhsgakWwAAAiA"]
[Mon Jun 15 20:17:00.250256 2026] [security2:error] [pid 51003:tid 51186] [client 213.180.203.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyHMpsKyvb75pkSvaLLAAAAcQ"]
[Mon Jun 15 20:17:00.251382 2026] [security2:error] [pid 51003:tid 51011] [remote 82.165.2.98:33752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.2.165.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sriramsidd.com"] [uri "/wp-login.php"] [unique_id "ajCyHMpsKyvb75pkSvaLLQABkAc"]
[Mon Jun 15 20:17:00.253071 2026] [security2:error] [pid 51003:tid 51248] [client 213.180.203.9:39746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyHMpsKyvb75pkSvaLJwACAhc"]
[Mon Jun 15 20:17:00.402773 2026] [security2:error] [pid 53359:tid 53568] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/admin/uploads/"] [unique_id "ajCyHPC2Xs1VMQlhsgakZgAAAl0"]
[Mon Jun 15 20:17:00.443070 2026] [security2:error] [pid 53359:tid 53495] [client 103.125.146.42:43203] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/radio.php"] [unique_id "ajCyHPC2Xs1VMQlhsgakagAAAhQ"]
[Mon Jun 15 20:17:00.469931 2026] [autoindex:error] [pid 51003:tid 51236] [client 82.102.18.118:0] AH01276: Cannot serve directory /home3/itjbthmy/public_html/jcpenneysurvey1/wp-includes/sodium_compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:17:00.470424 2026] [security2:error] [pid 51003:tid 51236] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCyHMpsKyvb75pkSvaLMwAAAfY"]
[Mon Jun 15 20:17:00.473996 2026] [security2:error] [pid 53359:tid 53543] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-includes/sodium_compat/"] [unique_id "ajCyHPC2Xs1VMQlhsgakaAAAAkQ"]
[Mon Jun 15 20:17:00.490073 2026] [security2:error] [pid 51003:tid 51082] [remote 82.165.2.98:33752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.2.165.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sriramsidd.com"] [uri "/wp-login.php"] [unique_id "ajCyHMpsKyvb75pkSvaLNAABzE4"], referer: https://sriramsidd.com/wp-login.php
[Mon Jun 15 20:17:00.562627 2026] [security2:error] [pid 51003:tid 51143] [client 52.167.144.173:3954] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ybsolutions.in"] [uri "/index.php"] [unique_id "ajCyHMpsKyvb75pkSvaLNwABmS0"]
[Mon Jun 15 20:17:00.647205 2026] [security2:error] [pid 53359:tid 53586] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-includes/style-engine/"] [unique_id "ajCyHPC2Xs1VMQlhsgakcgAAAm8"]
[Mon Jun 15 20:17:00.719868 2026] [security2:error] [pid 53359:tid 53596] [client 85.204.70.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyHPC2Xs1VMQlhsgakcwAAAnk"]
[Mon Jun 15 20:17:00.719893 2026] [security2:error] [pid 53359:tid 53596] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyHPC2Xs1VMQlhsgakcwAAAnk"]
[Mon Jun 15 20:17:00.725508 2026] [security2:error] [pid 53359:tid 53519] [client 85.204.70.112:59978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/admin/uploads/"] [unique_id "ajCyHPC2Xs1VMQlhsgakcAAAAiw"]
[Mon Jun 15 20:17:00.726186 2026] [security2:error] [pid 51003:tid 51173] [client 31.219.209.201:63062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.209.219.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCyHMpsKyvb75pkSvaLOQAAAbc"]
[Mon Jun 15 20:17:00.726292 2026] [security2:error] [pid 51003:tid 51173] [client 31.219.209.201:63062] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCyHMpsKyvb75pkSvaLOQAAAbc"]
[Mon Jun 15 20:17:00.799170 2026] [security2:error] [pid 51003:tid 51198] [client 87.250.224.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyHMpsKyvb75pkSvaLOwAAAdA"]
[Mon Jun 15 20:17:00.803312 2026] [security2:error] [pid 51003:tid 51259] [client 87.250.224.132:54570] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyHMpsKyvb75pkSvaLOAACDRs"]
[Mon Jun 15 20:17:00.855889 2026] [security2:error] [pid 53359:tid 53509] [client 103.125.146.50:62053] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/admin.php"] [unique_id "ajCyHPC2Xs1VMQlhsgakfAAAAiI"]
[Mon Jun 15 20:17:00.871865 2026] [autoindex:error] [pid 53359:tid 53541] [client 82.102.18.118:0] AH01276: Cannot serve directory /home3/itjbthmy/public_html/jcpenneysurvey1/wp-includes/style-engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:17:00.872352 2026] [security2:error] [pid 53359:tid 53541] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCyHPC2Xs1VMQlhsgakfQAAAkI"]
[Mon Jun 15 20:17:00.892090 2026] [security2:error] [pid 53359:tid 53603] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/Admin/uploads/"] [unique_id "ajCyHPC2Xs1VMQlhsgakgQAAAoA"]
[Mon Jun 15 20:17:00.900003 2026] [security2:error] [pid 53359:tid 53559] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-includes/style-engine/"] [unique_id "ajCyHPC2Xs1VMQlhsgakegAAAlQ"]
[Mon Jun 15 20:17:01.051736 2026] [security2:error] [pid 53359:tid 53564] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-includes/theme-compat/"] [unique_id "ajCyHfC2Xs1VMQlhsgakhAAAAlk"]
[Mon Jun 15 20:17:01.129546 2026] [security2:error] [pid 51003:tid 51183] [client 85.204.70.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyHcpsKyvb75pkSvaLRQAAAcE"]
[Mon Jun 15 20:17:01.129566 2026] [security2:error] [pid 51003:tid 51183] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyHcpsKyvb75pkSvaLRQAAAcE"]
[Mon Jun 15 20:17:01.134189 2026] [security2:error] [pid 53359:tid 53561] [client 85.204.70.112:59978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/Admin/uploads/"] [unique_id "ajCyHfC2Xs1VMQlhsgakgwAAAlY"]
[Mon Jun 15 20:17:01.207695 2026] [security2:error] [pid 51003:tid 51220] [client 213.180.203.244:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyHcpsKyvb75pkSvaLSgAAAeY"]
[Mon Jun 15 20:17:01.213979 2026] [security2:error] [pid 53359:tid 53533] [client 213.180.203.244:38122] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyHfC2Xs1VMQlhsgakiAACOk4"]
[Mon Jun 15 20:17:01.265702 2026] [autoindex:error] [pid 53359:tid 53606] [client 82.102.18.118:0] AH01276: Cannot serve directory /home3/itjbthmy/public_html/jcpenneysurvey1/wp-includes/theme-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:17:01.266367 2026] [security2:error] [pid 53359:tid 53606] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCyHfC2Xs1VMQlhsgakjgAAAoM"]
[Mon Jun 15 20:17:01.270005 2026] [autoindex:error] [pid 51003:tid 51172] [client 101.42.46.71:50740] AH01276: Cannot serve directory /home1/rugqjjmy/public_html/unitedhealthgroupcorp/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.unitedhealthgroup-corp.com
[Mon Jun 15 20:17:01.314305 2026] [security2:error] [pid 53359:tid 53499] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/admin/"] [unique_id "ajCyHfC2Xs1VMQlhsgakkAAAAhg"]
[Mon Jun 15 20:17:01.323221 2026] [security2:error] [pid 53359:tid 53577] [client 103.125.146.66:20987] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/"] [unique_id "ajCyHfC2Xs1VMQlhsgakkQAAAmY"]
[Mon Jun 15 20:17:01.327454 2026] [security2:error] [pid 53359:tid 53605] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-includes/theme-compat/"] [unique_id "ajCyHfC2Xs1VMQlhsgakjAAAAoI"]
[Mon Jun 15 20:17:01.478997 2026] [security2:error] [pid 53359:tid 53609] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-includes/widgets/"] [unique_id "ajCyHfC2Xs1VMQlhsgaklQAAAoY"]
[Mon Jun 15 20:17:01.504060 2026] [security2:error] [pid 51003:tid 51249] [client 57.141.14.73:27946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyHcpsKyvb75pkSvaLUQACAx4"]
[Mon Jun 15 20:17:01.524422 2026] [rewrite:error] [pid 53359:tid 53457] [remote 38.49.209.74:39466] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:17:01.604881 2026] [security2:error] [pid 51003:tid 51233] [client 85.204.70.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyHcpsKyvb75pkSvaLVAAAAfM"]
[Mon Jun 15 20:17:01.604911 2026] [security2:error] [pid 51003:tid 51233] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyHcpsKyvb75pkSvaLVAAAAfM"]
[Mon Jun 15 20:17:01.637980 2026] [security2:error] [pid 53359:tid 53501] [client 85.204.70.112:59978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "geekjuggernaut.com"] [uri "/admin/"] [unique_id "ajCyHfC2Xs1VMQlhsgaklgAAAho"]
[Mon Jun 15 20:17:01.706190 2026] [autoindex:error] [pid 51003:tid 51165] [client 82.102.18.118:0] AH01276: Cannot serve directory /home3/itjbthmy/public_html/jcpenneysurvey1/wp-includes/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:17:01.706712 2026] [security2:error] [pid 51003:tid 51165] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCyHcpsKyvb75pkSvaLWQAAAa8"]
[Mon Jun 15 20:17:01.712933 2026] [security2:error] [pid 53359:tid 53617] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-includes/widgets/"] [unique_id "ajCyHfC2Xs1VMQlhsgakmwAAAo4"]
[Mon Jun 15 20:17:01.717860 2026] [security2:error] [pid 53359:tid 53553] [client 103.125.146.74:65095] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/theme-compat/"] [unique_id "ajCyHfC2Xs1VMQlhsgakqQAAAk4"]
[Mon Jun 15 20:17:01.867966 2026] [security2:error] [pid 53359:tid 53526] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-admin/css/colors/ectoplasm/"] [unique_id "ajCyHfC2Xs1VMQlhsgaksAAAAjM"]
[Mon Jun 15 20:17:01.908819 2026] [security2:error] [pid 53359:tid 53459] [remote 223.185.60.114:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.smgl.org"] [uri "/product-category/wholesale-sterling-silver-rings/prong-setting-rings-rings/"] [unique_id "ajCyHfC2Xs1VMQlhsgaktAACIl0"], referer: https://www.yandex.org/
[Mon Jun 15 20:17:01.964204 2026] [security2:error] [pid 53359:tid 53420] [remote 2a03:2880:f806:4b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ruchini.hemani.finance"] [uri "/index.php"] [unique_id "ajCyHfC2Xs1VMQlhsgakrwACLDY"]
[Mon Jun 15 20:17:02.074065 2026] [security2:error] [pid 53359:tid 53586] [client 85.204.70.112:59978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "geekjuggernaut.com"] [uri "/wp-admin/index.php"] [unique_id "ajCyHfC2Xs1VMQlhsgakrgAAAm8"]
[Mon Jun 15 20:17:02.088235 2026] [autoindex:error] [pid 53359:tid 53500] [client 82.102.18.118:47714] AH01276: Cannot serve directory /home3/itjbthmy/public_html/jcpenneysurvey1/wp-admin/css/colors/ectoplasm/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:17:02.088832 2026] [security2:error] [pid 53359:tid 53500] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-admin/css/colors/ectoplasm/"] [unique_id "ajCyHvC2Xs1VMQlhsgakvAAAAhk"]
[Mon Jun 15 20:17:02.095883 2026] [security2:error] [pid 53359:tid 53573] [client 103.125.146.61:64333] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp.php"] [unique_id "ajCyHvC2Xs1VMQlhsgakvgAAAmI"]
[Mon Jun 15 20:17:02.159334 2026] [security2:error] [pid 53359:tid 53542] [client 95.108.213.136:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyHvC2Xs1VMQlhsgakvwAAAkM"]
[Mon Jun 15 20:17:02.170440 2026] [security2:error] [pid 51003:tid 51247] [client 95.108.213.136:34116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyHspsKyvb75pkSvaLXwACATQ"]
[Mon Jun 15 20:17:02.194150 2026] [security2:error] [pid 53359:tid 53533] [client 213.180.203.155:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyHvC2Xs1VMQlhsgakwwAAAjo"]
[Mon Jun 15 20:17:02.197075 2026] [security2:error] [pid 51003:tid 51195] [client 213.180.203.155:51848] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyHspsKyvb75pkSvaLYgABzQw"]
[Mon Jun 15 20:17:02.245067 2026] [security2:error] [pid 53359:tid 53515] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-admin/css/colors/"] [unique_id "ajCyHvC2Xs1VMQlhsgakxgAAAig"]
[Mon Jun 15 20:17:02.259697 2026] [security2:error] [pid 53359:tid 53512] [client 85.204.70.112:59978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "geekjuggernaut.com"] [uri "/wp-login.php"] [unique_id "ajCyHvC2Xs1VMQlhsgakxAAAAiU"]
[Mon Jun 15 20:17:02.259853 2026] [security2:error] [pid 53359:tid 53512] [client 85.204.70.112:59978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "geekjuggernaut.com"] [uri "/wp-login.php"] [unique_id "ajCyHvC2Xs1VMQlhsgakxAAAAiU"]
[Mon Jun 15 20:17:02.412680 2026] [security2:error] [pid 53359:tid 53609] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/images/"] [unique_id "ajCyHvC2Xs1VMQlhsgakzgAAAoY"]
[Mon Jun 15 20:17:02.446610 2026] [autoindex:error] [pid 53359:tid 53616] [client 82.102.18.118:47714] AH01276: Cannot serve directory /home3/itjbthmy/public_html/jcpenneysurvey1/wp-admin/css/colors/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:17:02.447156 2026] [security2:error] [pid 53359:tid 53616] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-admin/css/colors/"] [unique_id "ajCyHvC2Xs1VMQlhsgakzAAAAo0"]
[Mon Jun 15 20:17:02.504955 2026] [security2:error] [pid 53359:tid 53617] [client 103.125.146.53:59091] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/css/"] [unique_id "ajCyHvC2Xs1VMQlhsgak0gAAAo4"]
[Mon Jun 15 20:17:02.555769 2026] [security2:error] [pid 53359:tid 53452] [remote 188.166.231.216:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.231.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fashionsfever.com"] [uri "/wp-login.php"] [unique_id "ajCyHvC2Xs1VMQlhsgak1AACdFY"]
[Mon Jun 15 20:17:02.590837 2026] [security2:error] [pid 53359:tid 53525] [client 66.249.84.35:59346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "diggysguide.com"] [uri "/index.php"] [unique_id "ajCyHvC2Xs1VMQlhsgak1QAAAjI"]
[Mon Jun 15 20:17:02.605840 2026] [security2:error] [pid 53359:tid 53619] [client 66.249.84.35:51049] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "diggysguide.com"] [uri "/index.php"] [unique_id "ajCyHvC2Xs1VMQlhsgak1gAAApA"]
[Mon Jun 15 20:17:02.632914 2026] [security2:error] [pid 53359:tid 53567] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/admin/images/slider/"] [unique_id "ajCyHvC2Xs1VMQlhsgak1wAAAlw"]
[Mon Jun 15 20:17:02.819675 2026] [security2:error] [pid 53359:tid 53585] [client 213.180.203.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyHvC2Xs1VMQlhsgak4wAAAm4"]
[Mon Jun 15 20:17:02.822539 2026] [security2:error] [pid 53359:tid 53523] [client 213.180.203.5:43340] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyHvC2Xs1VMQlhsgak4QACMG4"]
[Mon Jun 15 20:17:02.920108 2026] [security2:error] [pid 53359:tid 53592] [client 103.125.146.41:54219] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-admin/js/widgets/"] [unique_id "ajCyHvC2Xs1VMQlhsgak6wAAAnU"]
[Mon Jun 15 20:17:02.982774 2026] [security2:error] [pid 53359:tid 53481] [remote 223.178.214.44:39082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.214.178.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.12oxenterprises.co"] [uri "/wp-login.php"] [unique_id "ajCyHvC2Xs1VMQlhsgak7gACcXM"]
[Mon Jun 15 20:17:03.006383 2026] [security2:error] [pid 53359:tid 53572] [client 85.204.70.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyHvC2Xs1VMQlhsgak7QAAAmE"]
[Mon Jun 15 20:17:03.006407 2026] [security2:error] [pid 53359:tid 53572] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyHvC2Xs1VMQlhsgak7QAAAmE"]
[Mon Jun 15 20:17:03.082802 2026] [security2:error] [pid 51003:tid 51164] [client 82.102.18.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyHspsKyvb75pkSvaLaAAAAa4"]
[Mon Jun 15 20:17:03.082826 2026] [security2:error] [pid 51003:tid 51164] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyHspsKyvb75pkSvaLaAAAAa4"]
[Mon Jun 15 20:17:03.089671 2026] [security2:error] [pid 53359:tid 53554] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/admin/images/slider/"] [unique_id "ajCyHvC2Xs1VMQlhsgak5QAAAk8"]
[Mon Jun 15 20:17:03.132982 2026] [security2:error] [pid 53359:tid 53521] [client 85.204.70.112:38918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/images/"] [unique_id "ajCyHvC2Xs1VMQlhsgak6QAAAi4"]
[Mon Jun 15 20:17:03.134573 2026] [security2:error] [pid 53359:tid 53375] [remote 78.142.18.172:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thedentalethics.com"] [uri "/wp-login.php"] [unique_id "ajCyH_C2Xs1VMQlhsgak8AACRwk"]
[Mon Jun 15 20:17:03.223213 2026] [security2:error] [pid 53359:tid 53507] [client 5.255.231.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyH_C2Xs1VMQlhsgak8wAAAiA"]
[Mon Jun 15 20:17:03.240448 2026] [security2:error] [pid 51003:tid 51143] [client 5.255.231.51:64638] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyH8psKyvb75pkSvaLbgABmRw"]
[Mon Jun 15 20:17:03.245343 2026] [security2:error] [pid 53359:tid 53498] [client 82.102.18.118:34166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/admin/fckeditor/editor/filemanager/"] [unique_id "ajCyH_C2Xs1VMQlhsgak9gAAAhc"]
[Mon Jun 15 20:17:03.249688 2026] [security2:error] [pid 53359:tid 53366] [remote 110.249.202.142:19452] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.steelsalesco.com"] [uri "/duplex-steel-elbolets-supplier-manufacturer/"] [unique_id "ajCyH_C2Xs1VMQlhsgak9wACfQA"]
[Mon Jun 15 20:17:03.330240 2026] [security2:error] [pid 53359:tid 53574] [client 103.125.146.54:58699] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/worksec.php"] [unique_id "ajCyH_C2Xs1VMQlhsgak-gAAAmM"]
[Mon Jun 15 20:17:03.403128 2026] [security2:error] [pid 53359:tid 53506] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/assets/"] [unique_id "ajCyH_C2Xs1VMQlhsgak_QAAAh8"]
[Mon Jun 15 20:17:03.492994 2026] [security2:error] [pid 51003:tid 51202] [client 142.248.80.164:62806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.mikaan.in"] [uri "/___proxy_subdomain_webdisk/.env"] [unique_id "ajCyH8psKyvb75pkSvaLeAAAAdQ"]
[Mon Jun 15 20:17:03.493871 2026] [security2:error] [pid 51003:tid 51230] [client 142.248.80.164:62946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.mikaan.in"] [uri "/___proxy_subdomain_webdisk/backend/.env"] [unique_id "ajCyH8psKyvb75pkSvaLewAAAfA"]
[Mon Jun 15 20:17:03.494107 2026] [security2:error] [pid 53359:tid 53502] [client 142.248.80.164:62968] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.mikaan.in"] [uri "/___proxy_subdomain_webdisk/server/.env"] [unique_id "ajCyH_C2Xs1VMQlhsgalAwAAAhs"]
[Mon Jun 15 20:17:03.494384 2026] [security2:error] [pid 53359:tid 53621] [client 142.248.80.164:62860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webdisk.mikaan.in"] [uri "/___proxy_subdomain_webdisk/.env.backup"] [unique_id "ajCyH_C2Xs1VMQlhsgalAgAAApI"]
[Mon Jun 15 20:17:03.494392 2026] [security2:error] [pid 53359:tid 53567] [client 142.248.80.164:62926] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.mikaan.in"] [uri "/___proxy_subdomain_webdisk/app/.env"] [unique_id "ajCyH_C2Xs1VMQlhsgalBAAAAlw"]
[Mon Jun 15 20:17:03.495310 2026] [security2:error] [pid 51003:tid 51157] [client 142.248.80.164:62850] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webdisk.mikaan.in"] [uri "/___proxy_subdomain_webdisk/.env.bak"] [unique_id "ajCyH8psKyvb75pkSvaLfgAAAac"]
[Mon Jun 15 20:17:03.495876 2026] [security2:error] [pid 51003:tid 51260] [client 142.248.80.164:62964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.mikaan.in"] [uri "/___proxy_subdomain_webdisk/src/.env"] [unique_id "ajCyH8psKyvb75pkSvaLgQAAAg4"]
[Mon Jun 15 20:17:03.496352 2026] [security2:error] [pid 53359:tid 53603] [client 142.248.80.164:62936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.mikaan.in"] [uri "/___proxy_subdomain_webdisk/api/.env"] [unique_id "ajCyH_C2Xs1VMQlhsgalCQAAAoA"]
[Mon Jun 15 20:17:03.496827 2026] [security2:error] [pid 51003:tid 51163] [client 142.248.80.164:62974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.mikaan.in"] [uri "/___proxy_subdomain_webdisk/web/.env"] [unique_id "ajCyH8psKyvb75pkSvaLhAAAAa0"]
[Mon Jun 15 20:17:03.498090 2026] [security2:error] [pid 51003:tid 51177] [client 142.248.80.164:62952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.mikaan.in"] [uri "/___proxy_subdomain_webdisk/laravel/.env"] [unique_id "ajCyH8psKyvb75pkSvaLiAAAAbs"]
[Mon Jun 15 20:17:03.499165 2026] [security2:error] [pid 53359:tid 53547] [client 142.248.80.164:62896] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webdisk.mikaan.in"] [uri "/___proxy_subdomain_webdisk/.env.old"] [unique_id "ajCyH_C2Xs1VMQlhsgalDgAAAkg"]
[Mon Jun 15 20:17:03.518320 2026] [security2:error] [pid 53359:tid 53619] [client 91.92.40.173:38202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.40.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tampapowerwashers.com"] [uri "/wp-login.php"] [unique_id "ajCyH_C2Xs1VMQlhsgalAAAAApA"]
[Mon Jun 15 20:17:03.557747 2026] [security2:error] [pid 51003:tid 51089] [remote 47.128.16.138:17642] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rathpoint.com"] [uri "/robots.txt"] [unique_id "ajCyH8psKyvb75pkSvaLjgABsVU"]
[Mon Jun 15 20:17:03.689266 2026] [security2:error] [pid 51003:tid 51174] [client 85.204.70.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyH8psKyvb75pkSvaLjwAAAbg"]
[Mon Jun 15 20:17:03.689290 2026] [security2:error] [pid 51003:tid 51174] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyH8psKyvb75pkSvaLjwAAAbg"]
[Mon Jun 15 20:17:03.693081 2026] [security2:error] [pid 53359:tid 53570] [client 85.204.70.112:38918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/assets/"] [unique_id "ajCyH_C2Xs1VMQlhsgalEwAAAl8"]
[Mon Jun 15 20:17:03.716877 2026] [security2:error] [pid 53359:tid 53561] [client 95.108.213.212:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyH_C2Xs1VMQlhsgalIwAAAlY"]
[Mon Jun 15 20:17:03.720040 2026] [security2:error] [pid 53359:tid 53571] [client 95.108.213.212:43224] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyH_C2Xs1VMQlhsgalIQACYAM"]
[Mon Jun 15 20:17:03.721718 2026] [security2:error] [pid 51003:tid 51094] [remote 206.232.122.232:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.smgl.org"] [uri "/product-category/wholesale-sterling-silver-rings/prong-setting-rings-rings/"] [unique_id "ajCyH8psKyvb75pkSvaLmwABm1o"], referer: https://www.smgl.org/
[Mon Jun 15 20:17:03.737141 2026] [security2:error] [pid 51003:tid 51192] [client 82.102.18.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyH8psKyvb75pkSvaLdgAAAco"]
[Mon Jun 15 20:17:03.737166 2026] [security2:error] [pid 51003:tid 51192] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyH8psKyvb75pkSvaLdgAAAco"]
[Mon Jun 15 20:17:03.744097 2026] [security2:error] [pid 53359:tid 53617] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/admin/fckeditor/editor/filemanager/"] [unique_id "ajCyH_C2Xs1VMQlhsgak_gAAAo4"]
[Mon Jun 15 20:17:03.756785 2026] [security2:error] [pid 53359:tid 53436] [remote 78.142.18.172:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thedentalethics.com"] [uri "/wp-login.php"] [unique_id "ajCyH_C2Xs1VMQlhsgalKgACUEY"], referer: https://thedentalethics.com/wp-login.php
[Mon Jun 15 20:17:03.824696 2026] [security2:error] [pid 53359:tid 53598] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/"] [unique_id "ajCyH_C2Xs1VMQlhsgalMAAAAns"]
[Mon Jun 15 20:17:03.913165 2026] [security2:error] [pid 51003:tid 51153] [client 142.248.80.164:62974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.mikaan.in"] [uri "/___proxy_subdomain_webdisk/public/.env"] [unique_id "ajCyH8psKyvb75pkSvaLpgAAAaM"]
[Mon Jun 15 20:17:04.028175 2026] [security2:error] [pid 53359:tid 53515] [client 57.141.14.61:36428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyH_C2Xs1VMQlhsgalMwACKBM"]
[Mon Jun 15 20:17:04.046074 2026] [security2:error] [pid 53359:tid 53567] [client 82.102.18.118:55566] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/sites/default/files/"] [unique_id "ajCyIPC2Xs1VMQlhsgalRAAAAlw"]
[Mon Jun 15 20:17:04.154614 2026] [security2:error] [pid 53359:tid 53621] [client 85.204.70.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyIPC2Xs1VMQlhsgalRQAAApI"]
[Mon Jun 15 20:17:04.154644 2026] [security2:error] [pid 53359:tid 53621] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyIPC2Xs1VMQlhsgalRQAAApI"]
[Mon Jun 15 20:17:04.157631 2026] [security2:error] [pid 53359:tid 53525] [client 85.204.70.112:38918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/"] [unique_id "ajCyIPC2Xs1VMQlhsgalQwAAAjI"]
[Mon Jun 15 20:17:04.222390 2026] [security2:error] [pid 53359:tid 53610] [client 213.180.203.103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyIPC2Xs1VMQlhsgalSQAAAoc"]
[Mon Jun 15 20:17:04.255019 2026] [security2:error] [pid 51003:tid 51057] [remote 188.166.231.216:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.231.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fashionsfever.com"] [uri "/wp-login.php"] [unique_id "ajCyIMpsKyvb75pkSvaLuQABuzU"], referer: https://fashionsfever.com/wp-login.php
[Mon Jun 15 20:17:04.255533 2026] [security2:error] [pid 53359:tid 53530] [client 213.180.203.103:64434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyIPC2Xs1VMQlhsgalRwACN30"]
[Mon Jun 15 20:17:04.286888 2026] [security2:error] [pid 53359:tid 53576] [client 157.55.39.6:63832] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ybsolutions.in"] [uri "/index.php"] [unique_id "ajCyIPC2Xs1VMQlhsgalTAACZXk"]
[Mon Jun 15 20:17:04.320540 2026] [security2:error] [pid 53359:tid 53511] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/upload/image/"] [unique_id "ajCyIPC2Xs1VMQlhsgalTwAAAiQ"]
[Mon Jun 15 20:17:04.347571 2026] [security2:error] [pid 51003:tid 51175] [client 157.55.39.58:1878] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ybsolutions.in"] [uri "/index.php"] [unique_id "ajCyIMpsKyvb75pkSvaLvgABuSk"]
[Mon Jun 15 20:17:04.414865 2026] [security2:error] [pid 53359:tid 53519] [client 157.55.39.6:63832] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ybsolutions.in"] [uri "/index.php"] [unique_id "ajCyIPC2Xs1VMQlhsgalUwACLDg"]
[Mon Jun 15 20:17:04.587979 2026] [security2:error] [pid 51003:tid 51148] [client 82.102.18.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyIMpsKyvb75pkSvaLuwAAAZ4"]
[Mon Jun 15 20:17:04.588008 2026] [security2:error] [pid 51003:tid 51148] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyIMpsKyvb75pkSvaLuwAAAZ4"]
[Mon Jun 15 20:17:04.596924 2026] [security2:error] [pid 53359:tid 53599] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/sites/default/files/"] [unique_id "ajCyIPC2Xs1VMQlhsgalSwAAAnw"]
[Mon Jun 15 20:17:04.604380 2026] [security2:error] [pid 53359:tid 53555] [client 85.204.70.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyIPC2Xs1VMQlhsgalVwAAAlA"]
[Mon Jun 15 20:17:04.604414 2026] [security2:error] [pid 53359:tid 53555] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyIPC2Xs1VMQlhsgalVwAAAlA"]
[Mon Jun 15 20:17:04.635668 2026] [security2:error] [pid 53359:tid 53553] [client 85.204.70.112:38918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/upload/image/"] [unique_id "ajCyIPC2Xs1VMQlhsgalVgAAAk4"]
[Mon Jun 15 20:17:04.637037 2026] [security2:error] [pid 53359:tid 53510] [client 57.141.14.16:54756] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyIPC2Xs1VMQlhsgalVQACI1Q"]
[Mon Jun 15 20:17:04.749988 2026] [security2:error] [pid 53359:tid 53520] [client 82.102.18.118:55566] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/admin/controller/extension/extension/"] [unique_id "ajCyIPC2Xs1VMQlhsgalWQAAAi0"]
[Mon Jun 15 20:17:05.046632 2026] [security2:error] [pid 51003:tid 51238] [client 143.244.57.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.surveylaya.com"] [uri "/wp-content/plugins/index.php"] [unique_id "ajCyIcpsKyvb75pkSvaL0AAAAfg"]
[Mon Jun 15 20:17:05.049719 2026] [security2:error] [pid 53359:tid 53611] [client 143.244.57.120:40604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.surveylaya.com"] [uri "/wp-content/plugins/"] [unique_id "ajCyIfC2Xs1VMQlhsgalYQAAAog"]
[Mon Jun 15 20:17:05.061538 2026] [security2:error] [pid 53359:tid 53605] [client 85.204.70.112:38918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "geekjuggernaut.com"] [uri "/wp-content/uploads/2025/12/image.png"] [unique_id "ajCyIPC2Xs1VMQlhsgalWgAAAoI"]
[Mon Jun 15 20:17:05.095436 2026] [security2:error] [pid 53359:tid 53524] [client 95.108.213.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyIfC2Xs1VMQlhsgalZgAAAjE"]
[Mon Jun 15 20:17:05.140388 2026] [security2:error] [pid 53359:tid 53602] [client 95.108.213.143:54660] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyIfC2Xs1VMQlhsgalYwACfwg"]
[Mon Jun 15 20:17:05.226758 2026] [security2:error] [pid 51003:tid 51165] [client 82.102.18.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyIMpsKyvb75pkSvaLywAAAa8"]
[Mon Jun 15 20:17:05.226797 2026] [security2:error] [pid 51003:tid 51165] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyIMpsKyvb75pkSvaLywAAAa8"]
[Mon Jun 15 20:17:05.227408 2026] [security2:error] [pid 53359:tid 53531] [client 213.180.203.250:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyIfC2Xs1VMQlhsgalagAAAjg"]
[Mon Jun 15 20:17:05.229305 2026] [security2:error] [pid 51003:tid 51212] [client 213.180.203.250:54676] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyIcpsKyvb75pkSvaL0gAB3mw"]
[Mon Jun 15 20:17:05.231889 2026] [security2:error] [pid 53359:tid 53587] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/admin/controller/extension/extension/"] [unique_id "ajCyIPC2Xs1VMQlhsgalYAAAAnA"]
[Mon Jun 15 20:17:05.292932 2026] [security2:error] [pid 53359:tid 53504] [client 192.140.64.94:29740] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCyIfC2Xs1VMQlhsgalbAAAAh0"]
[Mon Jun 15 20:17:05.293080 2026] [security2:error] [pid 53359:tid 53504] [client 192.140.64.94:29740] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCyIfC2Xs1VMQlhsgalbAAAAh0"]
[Mon Jun 15 20:17:05.307590 2026] [security2:error] [pid 51003:tid 51198] [client 45.238.43.182:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kthemani.com"] [uri "/index.php"] [unique_id "ajCyH8psKyvb75pkSvaLcQAAAdA"]
[Mon Jun 15 20:17:05.424948 2026] [security2:error] [pid 53359:tid 53595] [client 82.102.18.118:55566] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/"] [unique_id "ajCyIfC2Xs1VMQlhsgalbgAAAng"]
[Mon Jun 15 20:17:05.472139 2026] [security2:error] [pid 53359:tid 53541] [client 17.246.19.64:54430] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "wantpg.com"] [uri "/public/index.php/pg-in-kharkhasa-32091"] [unique_id "ajCyIfC2Xs1VMQlhsgalcAACQg0"]
[Mon Jun 15 20:17:05.612396 2026] [security2:error] [pid 51003:tid 51005] [remote 107.172.188.255:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.smgl.org"] [uri "/product-category/wholesale-sterling-silver-rings/prong-setting-rings-rings/"] [unique_id "ajCyIcpsKyvb75pkSvaL3wABogE"]
[Mon Jun 15 20:17:05.715528 2026] [security2:error] [pid 51003:tid 51230] [client 5.255.231.114:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyIcpsKyvb75pkSvaL4gAAAfA"]
[Mon Jun 15 20:17:05.718172 2026] [security2:error] [pid 53359:tid 53545] [client 5.255.231.114:44512] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyIfC2Xs1VMQlhsgaleAACRhQ"]
[Mon Jun 15 20:17:05.763345 2026] [security2:error] [pid 53359:tid 53554] [client 57.141.14.8:24063] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fifthestate.agency"] [uri "/index.php"] [unique_id "ajCyIfC2Xs1VMQlhsgalcgACTxg"]
[Mon Jun 15 20:17:05.836897 2026] [security2:error] [pid 51003:tid 51201] [client 82.102.18.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyIcpsKyvb75pkSvaL4AAAAdM"]
[Mon Jun 15 20:17:05.836929 2026] [security2:error] [pid 51003:tid 51201] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyIcpsKyvb75pkSvaL4AAAAdM"]
[Mon Jun 15 20:17:05.843428 2026] [security2:error] [pid 53359:tid 53617] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/"] [unique_id "ajCyIfC2Xs1VMQlhsgaldQAAAo4"]
[Mon Jun 15 20:17:05.922219 2026] [security2:error] [pid 53359:tid 53557] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/assets/images/"] [unique_id "ajCyIfC2Xs1VMQlhsgalfAAAAlI"]
[Mon Jun 15 20:17:06.015274 2026] [security2:error] [pid 53359:tid 53520] [client 82.102.18.118:55566] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/components/"] [unique_id "ajCyIvC2Xs1VMQlhsgalfgAAAi0"]
[Mon Jun 15 20:17:06.195825 2026] [security2:error] [pid 53359:tid 53501] [client 57.141.14.85:45800] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyIvC2Xs1VMQlhsgalgQACGl8"]
[Mon Jun 15 20:17:06.202504 2026] [security2:error] [pid 51003:tid 51235] [client 85.204.70.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyIspsKyvb75pkSvaL8AAAAfU"]
[Mon Jun 15 20:17:06.202531 2026] [security2:error] [pid 51003:tid 51235] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyIspsKyvb75pkSvaL8AAAAfU"]
[Mon Jun 15 20:17:06.206212 2026] [security2:error] [pid 53359:tid 53528] [client 85.204.70.112:38918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/assets/images/"] [unique_id "ajCyIvC2Xs1VMQlhsgalhAAAAjU"]
[Mon Jun 15 20:17:06.222065 2026] [security2:error] [pid 53359:tid 53578] [client 34.178.228.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.brainstrom.org"] [uri "/index.php"] [unique_id "ajCyIvC2Xs1VMQlhsgalgwACZz4"], referer: http://www.brainstrom.org/feed
[Mon Jun 15 20:17:06.392307 2026] [security2:error] [pid 53359:tid 53549] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/Public/"] [unique_id "ajCyIvC2Xs1VMQlhsgallwAAAko"]
[Mon Jun 15 20:17:06.434993 2026] [security2:error] [pid 53359:tid 53506] [client 82.102.18.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyIvC2Xs1VMQlhsgaljwAAAh8"]
[Mon Jun 15 20:17:06.435010 2026] [security2:error] [pid 53359:tid 53506] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyIvC2Xs1VMQlhsgaljwAAAh8"]
[Mon Jun 15 20:17:06.441817 2026] [security2:error] [pid 53359:tid 53518] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/components/"] [unique_id "ajCyIvC2Xs1VMQlhsgaliQAAAis"]
[Mon Jun 15 20:17:06.482434 2026] [security2:error] [pid 53359:tid 53467] [remote 74.7.243.250:34062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rentswale.ehx.czu.mybluehostin.me"] [uri "/css/admin/uploads/item/admin/uploads/icon/js/images/company_ifo.php"] [unique_id "ajCyIvC2Xs1VMQlhsgalmAACPGU"], referer: https://rentswale.ehx.czu.mybluehostin.me/css/admin/uploads/item/admin/uploads/icon/js/images/ios.svg
[Mon Jun 15 20:17:06.622273 2026] [security2:error] [pid 53359:tid 53530] [client 82.102.18.118:55566] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/admin/uploads/images/"] [unique_id "ajCyIvC2Xs1VMQlhsgalnQAAAjc"]
[Mon Jun 15 20:17:06.767092 2026] [security2:error] [pid 53359:tid 53560] [client 109.70.100.4:47076] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "gamergreatness.com"] [uri "/index.php"] [unique_id "ajCyIvC2Xs1VMQlhsgalnAACVSU"], referer: https://gamergreatness.com/community/topic/whats-your-all-time-favorite-anime
[Mon Jun 15 20:17:06.767315 2026] [security2:error] [pid 53359:tid 53576] [client 85.204.70.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyIvC2Xs1VMQlhsgalowAAAmU"]
[Mon Jun 15 20:17:06.767346 2026] [security2:error] [pid 53359:tid 53576] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyIvC2Xs1VMQlhsgalowAAAmU"]
[Mon Jun 15 20:17:06.779446 2026] [security2:error] [pid 53359:tid 53529] [client 85.204.70.112:38918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/Public/"] [unique_id "ajCyIvC2Xs1VMQlhsgalmQAAAjY"]
[Mon Jun 15 20:17:06.841622 2026] [security2:error] [pid 53359:tid 53431] [remote 82.223.68.64:51442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.68.223.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lekshey.org"] [uri "/wp-login.php"] [unique_id "ajCyIvC2Xs1VMQlhsgalqAACGUE"]
[Mon Jun 15 20:17:06.910035 2026] [security2:error] [pid 53359:tid 53533] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/vendor/"] [unique_id "ajCyIvC2Xs1VMQlhsgalqQAAAjo"]
[Mon Jun 15 20:17:07.030811 2026] [security2:error] [pid 53359:tid 53541] [client 82.102.18.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyIvC2Xs1VMQlhsgalpgAAAkI"]
[Mon Jun 15 20:17:07.030833 2026] [security2:error] [pid 53359:tid 53541] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyIvC2Xs1VMQlhsgalpgAAAkI"]
[Mon Jun 15 20:17:07.037959 2026] [security2:error] [pid 53359:tid 53511] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/admin/uploads/images/"] [unique_id "ajCyIvC2Xs1VMQlhsgalpAAAAiQ"]
[Mon Jun 15 20:17:07.141118 2026] [security2:error] [pid 53359:tid 53413] [remote 82.223.68.64:51442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.68.223.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lekshey.org"] [uri "/wp-login.php"] [unique_id "ajCyI_C2Xs1VMQlhsgalrQACky8"], referer: https://lekshey.org/wp-login.php
[Mon Jun 15 20:17:07.234628 2026] [security2:error] [pid 53359:tid 53597] [client 82.102.18.118:55566] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-content/plugins/classic-editor/"] [unique_id "ajCyI_C2Xs1VMQlhsgalrwAAAno"]
[Mon Jun 15 20:17:07.235347 2026] [security2:error] [pid 51003:tid 51134] [client 85.204.70.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyI8psKyvb75pkSvaMCQAAAZA"]
[Mon Jun 15 20:17:07.235371 2026] [security2:error] [pid 51003:tid 51134] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyI8psKyvb75pkSvaMCQAAAZA"]
[Mon Jun 15 20:17:07.236994 2026] [security2:error] [pid 53359:tid 53542] [client 85.204.70.112:38918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/vendor/"] [unique_id "ajCyI_C2Xs1VMQlhsgalqwAAAkM"]
[Mon Jun 15 20:17:07.417387 2026] [security2:error] [pid 53359:tid 53613] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/local/"] [unique_id "ajCyI_C2Xs1VMQlhsgaltwAAAoo"]
[Mon Jun 15 20:17:07.617261 2026] [security2:error] [pid 53359:tid 53429] [remote 57.141.14.74:32250] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyI_C2Xs1VMQlhsgaluQACMT8"]
[Mon Jun 15 20:17:07.651842 2026] [security2:error] [pid 51003:tid 51206] [client 82.102.18.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyI8psKyvb75pkSvaMEAAAAdg"]
[Mon Jun 15 20:17:07.651868 2026] [security2:error] [pid 51003:tid 51206] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyI8psKyvb75pkSvaMEAAAAdg"]
[Mon Jun 15 20:17:07.660108 2026] [security2:error] [pid 53359:tid 53606] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-content/plugins/classic-editor/"] [unique_id "ajCyI_C2Xs1VMQlhsgalswAAAoM"]
[Mon Jun 15 20:17:07.738006 2026] [security2:error] [pid 53359:tid 53534] [client 85.204.70.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyI_C2Xs1VMQlhsgalwAAAAjs"]
[Mon Jun 15 20:17:07.738028 2026] [security2:error] [pid 53359:tid 53534] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyI_C2Xs1VMQlhsgalwAAAAjs"]
[Mon Jun 15 20:17:07.742382 2026] [security2:error] [pid 53359:tid 53603] [client 85.204.70.112:38918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/local/"] [unique_id "ajCyI_C2Xs1VMQlhsgalvgAAAoA"]
[Mon Jun 15 20:17:07.818977 2026] [security2:error] [pid 53359:tid 53529] [client 82.102.18.118:55566] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-content/fonts/"] [unique_id "ajCyI_C2Xs1VMQlhsgalxQAAAjY"]
[Mon Jun 15 20:17:07.916230 2026] [security2:error] [pid 53359:tid 53519] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/modules/"] [unique_id "ajCyI_C2Xs1VMQlhsgalyAAAAiw"]
[Mon Jun 15 20:17:07.980510 2026] [security2:error] [pid 53359:tid 53500] [client 95.108.213.209:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyI_C2Xs1VMQlhsgalywAAAhk"]
[Mon Jun 15 20:17:07.993031 2026] [security2:error] [pid 53359:tid 53480] [remote 184.107.244.93:39456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.244.107.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fifthestate.agency"] [uri "/wp-login.php"] [unique_id "ajCyI_C2Xs1VMQlhsgalzwACdXI"]
[Mon Jun 15 20:17:08.002440 2026] [security2:error] [pid 53359:tid 53570] [client 95.108.213.209:43958] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyI_C2Xs1VMQlhsgalyQACX3Y"]
[Mon Jun 15 20:17:08.200374 2026] [security2:error] [pid 53359:tid 53582] [client 85.204.70.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyJPC2Xs1VMQlhsgal1wAAAms"]
[Mon Jun 15 20:17:08.200399 2026] [security2:error] [pid 53359:tid 53582] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyJPC2Xs1VMQlhsgal1wAAAms"]
[Mon Jun 15 20:17:08.204970 2026] [security2:error] [pid 53359:tid 53511] [client 85.204.70.112:38918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/modules/"] [unique_id "ajCyJPC2Xs1VMQlhsgal0wAAAiQ"]
[Mon Jun 15 20:17:08.230221 2026] [security2:error] [pid 53359:tid 53599] [client 82.102.18.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyJPC2Xs1VMQlhsgal0gAAAnw"]
[Mon Jun 15 20:17:08.230240 2026] [security2:error] [pid 53359:tid 53599] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyJPC2Xs1VMQlhsgal0gAAAnw"]
[Mon Jun 15 20:17:08.231216 2026] [security2:error] [pid 53359:tid 53439] [remote 184.107.244.93:39456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.244.107.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fifthestate.agency"] [uri "/wp-login.php"] [unique_id "ajCyJPC2Xs1VMQlhsgal2wACXEk"], referer: https://fifthestate.agency/wp-login.php
[Mon Jun 15 20:17:08.234352 2026] [security2:error] [pid 53359:tid 53601] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-content/fonts/"] [unique_id "ajCyI_C2Xs1VMQlhsgalzQAAAn4"]
[Mon Jun 15 20:17:08.338352 2026] [security2:error] [pid 53359:tid 53515] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/Site/"] [unique_id "ajCyJPC2Xs1VMQlhsgal4AAAAig"]
[Mon Jun 15 20:17:08.421692 2026] [security2:error] [pid 53359:tid 53509] [client 82.102.18.118:55566] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-content/plugins/contact-form-7/admin/js/"] [unique_id "ajCyJPC2Xs1VMQlhsgal4QAAAiI"]
[Mon Jun 15 20:17:08.483268 2026] [security2:error] [pid 53359:tid 53523] [client 177.225.95.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "travelmax.in"] [uri "/index.php"] [unique_id "ajCyJPC2Xs1VMQlhsgal3QACMGw"]
[Mon Jun 15 20:17:08.602214 2026] [security2:error] [pid 51003:tid 51159] [client 85.204.70.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyJMpsKyvb75pkSvaMHQAAAak"]
[Mon Jun 15 20:17:08.602236 2026] [security2:error] [pid 51003:tid 51159] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyJMpsKyvb75pkSvaMHQAAAak"]
[Mon Jun 15 20:17:08.602509 2026] [rewrite:error] [pid 53359:tid 53574] [client 47.79.199.122:6922] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:17:08.609696 2026] [security2:error] [pid 53359:tid 53395] [remote 104.233.47.151:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.smgl.org"] [uri "/product-category/wholesale-sterling-silver-rings/prong-setting-rings-rings/"] [unique_id "ajCyJPC2Xs1VMQlhsgal7AACTR0"], referer: https://www.smgl.org/
[Mon Jun 15 20:17:08.614311 2026] [security2:error] [pid 53359:tid 53530] [client 85.204.70.112:38918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/Site/"] [unique_id "ajCyJPC2Xs1VMQlhsgal5wAAAjc"]
[Mon Jun 15 20:17:08.743083 2026] [security2:error] [pid 53359:tid 53571] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/system/"] [unique_id "ajCyJPC2Xs1VMQlhsgal8AAAAmA"]
[Mon Jun 15 20:17:08.819808 2026] [security2:error] [pid 51003:tid 51204] [client 82.102.18.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyJMpsKyvb75pkSvaMHgAAAdY"]
[Mon Jun 15 20:17:08.819830 2026] [security2:error] [pid 51003:tid 51204] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyJMpsKyvb75pkSvaMHgAAAdY"]
[Mon Jun 15 20:17:08.841930 2026] [security2:error] [pid 53359:tid 53506] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-content/plugins/contact-form-7/admin/js/"] [unique_id "ajCyJPC2Xs1VMQlhsgal6QAAAh8"]
[Mon Jun 15 20:17:08.919915 2026] [security2:error] [pid 51003:tid 51137] [client 103.125.146.43:59123] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/themes/"] [unique_id "ajCyJMpsKyvb75pkSvaMJQAAAZM"]
[Mon Jun 15 20:17:08.993208 2026] [security2:error] [pid 53359:tid 53554] [client 82.102.18.118:55566] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-content/plugins/contact-form-7/"] [unique_id "ajCyJPC2Xs1VMQlhsgal-AAAAk8"]
[Mon Jun 15 20:17:09.011229 2026] [security2:error] [pid 53359:tid 53585] [client 85.204.70.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyJPC2Xs1VMQlhsgal9gAAAm4"]
[Mon Jun 15 20:17:09.011247 2026] [security2:error] [pid 53359:tid 53585] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyJPC2Xs1VMQlhsgal9gAAAm4"]
[Mon Jun 15 20:17:09.016079 2026] [security2:error] [pid 53359:tid 53536] [client 85.204.70.112:38918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/system/"] [unique_id "ajCyJPC2Xs1VMQlhsgal8gAAAj0"]
[Mon Jun 15 20:17:09.088773 2026] [rewrite:error] [pid 53359:tid 53510] [client 47.79.199.122:6922] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:17:09.202124 2026] [security2:error] [pid 53359:tid 53600] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/template/"] [unique_id "ajCyJfC2Xs1VMQlhsgamAAAAAn0"]
[Mon Jun 15 20:17:09.399501 2026] [security2:error] [pid 53359:tid 53501] [client 57.141.14.42:45766] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyJfC2Xs1VMQlhsgamAwACGjI"]
[Mon Jun 15 20:17:09.399579 2026] [security2:error] [pid 53359:tid 53617] [client 82.102.18.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyJfC2Xs1VMQlhsgal_QAAAo4"]
[Mon Jun 15 20:17:09.399597 2026] [security2:error] [pid 53359:tid 53617] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyJfC2Xs1VMQlhsgal_QAAAo4"]
[Mon Jun 15 20:17:09.403258 2026] [security2:error] [pid 53359:tid 53545] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-content/plugins/contact-form-7/"] [unique_id "ajCyJfC2Xs1VMQlhsgal-gAAAkY"]
[Mon Jun 15 20:17:09.426040 2026] [security2:error] [pid 53359:tid 53553] [client 65.111.15.212:47949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.15.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rajunandkardeputycollector.blog"] [uri "/wp-login.php"] [unique_id "ajCyJfC2Xs1VMQlhsgamDQAAAk4"], referer: https://rajunandkardeputycollector.blog/wp-login.php
[Mon Jun 15 20:17:09.438477 2026] [security2:error] [pid 53359:tid 53499] [client 85.204.70.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyJfC2Xs1VMQlhsgamCQAAAhg"]
[Mon Jun 15 20:17:09.438496 2026] [security2:error] [pid 53359:tid 53499] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyJfC2Xs1VMQlhsgamCQAAAhg"]
[Mon Jun 15 20:17:09.483187 2026] [security2:error] [pid 53359:tid 53578] [client 85.204.70.112:38918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/template/"] [unique_id "ajCyJfC2Xs1VMQlhsgamBgAAAmc"]
[Mon Jun 15 20:17:09.487879 2026] [security2:error] [pid 53359:tid 53535] [client 103.125.146.79:31635] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wordpress/wp-admin/maint/"] [unique_id "ajCyJfC2Xs1VMQlhsgamEAAAAjw"]
[Mon Jun 15 20:17:09.556057 2026] [security2:error] [pid 53359:tid 53508] [client 82.102.18.118:55566] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wordpress/"] [unique_id "ajCyJfC2Xs1VMQlhsgamEQAAAiE"]
[Mon Jun 15 20:17:09.612824 2026] [security2:error] [pid 53359:tid 53576] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/shop/"] [unique_id "ajCyJfC2Xs1VMQlhsgamEwAAAmU"]
[Mon Jun 15 20:17:09.714377 2026] [security2:error] [pid 53359:tid 53435] [remote 47.128.33.100:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mywordsnthoughts.com"] [uri "/sago-pudding-with-coconut/"] [unique_id "ajCyJfC2Xs1VMQlhsgamFQAChkU"]
[Mon Jun 15 20:17:09.843063 2026] [security2:error] [pid 51003:tid 51171] [client 85.204.70.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyJcpsKyvb75pkSvaMMwAAAbU"]
[Mon Jun 15 20:17:09.843085 2026] [security2:error] [pid 51003:tid 51171] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyJcpsKyvb75pkSvaMMwAAAbU"]
[Mon Jun 15 20:17:09.847138 2026] [security2:error] [pid 53359:tid 53574] [client 85.204.70.112:38918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/shop/"] [unique_id "ajCyJfC2Xs1VMQlhsgamGQAAAmM"]
[Mon Jun 15 20:17:09.876533 2026] [security2:error] [pid 53359:tid 53522] [client 57.141.14.84:27396] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fifthestate.agency"] [uri "/index.php"] [unique_id "ajCyJfC2Xs1VMQlhsgamFAACL0s"]
[Mon Jun 15 20:17:09.890992 2026] [security2:error] [pid 53359:tid 53517] [client 103.125.146.50:60873] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/themes/404.php"] [unique_id "ajCyJfC2Xs1VMQlhsgamHgAAAio"]
[Mon Jun 15 20:17:09.916373 2026] [rewrite:error] [pid 53359:tid 53471] [remote 47.79.199.109:30956] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:17:09.994118 2026] [security2:error] [pid 53359:tid 53561] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/files/"] [unique_id "ajCyJfC2Xs1VMQlhsgamJAAAAlY"]
[Mon Jun 15 20:17:09.999714 2026] [security2:error] [pid 53359:tid 53603] [client 65.111.29.118:50901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.29.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rajunandkardeputycollector.blog"] [uri "/wp-login.php"] [unique_id "ajCyJfC2Xs1VMQlhsgamIwAAAoA"], referer: https://rajunandkardeputycollector.blog/wp-login.php
[Mon Jun 15 20:17:10.004253 2026] [security2:error] [pid 53359:tid 53616] [client 82.102.18.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyJfC2Xs1VMQlhsgamGwAAAo0"]
[Mon Jun 15 20:17:10.004274 2026] [security2:error] [pid 53359:tid 53616] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyJfC2Xs1VMQlhsgamGwAAAo0"]
[Mon Jun 15 20:17:10.007963 2026] [security2:error] [pid 53359:tid 53605] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wordpress/"] [unique_id "ajCyJfC2Xs1VMQlhsgamFgAAAoI"]
[Mon Jun 15 20:17:10.166964 2026] [rewrite:error] [pid 53359:tid 53449] [remote 47.79.199.109:30956] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:17:10.205635 2026] [security2:error] [pid 53359:tid 53598] [client 87.250.224.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyJvC2Xs1VMQlhsgamLgAAAns"]
[Mon Jun 15 20:17:10.207931 2026] [security2:error] [pid 53359:tid 53529] [client 87.250.224.34:45164] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyJvC2Xs1VMQlhsgamKAACNgw"]
[Mon Jun 15 20:17:10.245846 2026] [security2:error] [pid 53359:tid 53592] [client 85.204.70.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyJvC2Xs1VMQlhsgamLwAAAnU"]
[Mon Jun 15 20:17:10.245871 2026] [security2:error] [pid 53359:tid 53592] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyJvC2Xs1VMQlhsgamLwAAAnU"]
[Mon Jun 15 20:17:10.249082 2026] [security2:error] [pid 53359:tid 53543] [client 82.102.18.118:55566] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-admin/images/"] [unique_id "ajCyJvC2Xs1VMQlhsgamMAAAAkQ"]
[Mon Jun 15 20:17:10.253306 2026] [security2:error] [pid 51003:tid 51123] [remote 107.172.26.151:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.smgl.org"] [uri "/"] [unique_id "ajCyJspsKyvb75pkSvaMPQAB2Hc"], referer: https://www.smgl.org/
[Mon Jun 15 20:17:10.272910 2026] [security2:error] [pid 53359:tid 53585] [client 85.204.70.112:38918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/files/"] [unique_id "ajCyJvC2Xs1VMQlhsgamKgAAAm4"]
[Mon Jun 15 20:17:10.312238 2026] [security2:error] [pid 53359:tid 53600] [client 103.125.146.75:51331] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/plugins/hello.php"] [unique_id "ajCyJvC2Xs1VMQlhsgamMQAAAn0"]
[Mon Jun 15 20:17:10.411342 2026] [security2:error] [pid 53359:tid 53567] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/admin/editor/"] [unique_id "ajCyJvC2Xs1VMQlhsgamMgAAAlw"]
[Mon Jun 15 20:17:10.473586 2026] [autoindex:error] [pid 53359:tid 53593] [client 82.102.18.118:47714] AH01276: Cannot serve directory /home3/itjbthmy/public_html/jcpenneysurvey1/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:17:10.474208 2026] [security2:error] [pid 53359:tid 53593] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-admin/images/"] [unique_id "ajCyJvC2Xs1VMQlhsgamMwAAAnY"]
[Mon Jun 15 20:17:10.630242 2026] [security2:error] [pid 53359:tid 53578] [client 82.102.18.118:55566] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-content/plugins/wordpress-seo/js/dist/"] [unique_id "ajCyJvC2Xs1VMQlhsgamOAAAAmc"]
[Mon Jun 15 20:17:10.737167 2026] [security2:error] [pid 53359:tid 53504] [client 103.125.146.64:55463] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/index/function.php"] [unique_id "ajCyJvC2Xs1VMQlhsgamQAAAAh0"]
[Mon Jun 15 20:17:10.740316 2026] [security2:error] [pid 51003:tid 51026] [remote 213.171.208.62:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.208.171.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "travelmax.in"] [uri "/wp-login.php"] [unique_id "ajCyJspsKyvb75pkSvaMSgABpxY"]
[Mon Jun 15 20:17:10.744541 2026] [security2:error] [pid 53359:tid 53524] [client 47.79.206.96:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "db.geeksinsight.com"] [uri "/index.php"] [unique_id "ajCyJvC2Xs1VMQlhsgamPAAAAjE"], referer: https://www.google.com/
[Mon Jun 15 20:17:10.746871 2026] [security2:error] [pid 51003:tid 51185] [client 85.204.70.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyJspsKyvb75pkSvaMRwAAAcM"]
[Mon Jun 15 20:17:10.746891 2026] [security2:error] [pid 51003:tid 51185] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyJspsKyvb75pkSvaMRwAAAcM"]
[Mon Jun 15 20:17:10.748769 2026] [security2:error] [pid 53359:tid 53499] [client 85.204.70.112:38918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/admin/editor/"] [unique_id "ajCyJvC2Xs1VMQlhsgamNgAAAhg"]
[Mon Jun 15 20:17:10.857490 2026] [autoindex:error] [pid 53359:tid 53539] [client 82.102.18.118:0] AH01276: Cannot serve directory /home3/itjbthmy/public_html/jcpenneysurvey1/wp-content/plugins/wordpress-seo/js/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:17:10.858130 2026] [security2:error] [pid 53359:tid 53539] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCyJvC2Xs1VMQlhsgamRQAAAkA"]
[Mon Jun 15 20:17:10.859986 2026] [security2:error] [pid 53359:tid 53464] [remote 57.141.14.15:40131] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyJvC2Xs1VMQlhsgamPwACK2I"]
[Mon Jun 15 20:17:10.860620 2026] [security2:error] [pid 53359:tid 53495] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-content/plugins/wordpress-seo/js/dist/"] [unique_id "ajCyJvC2Xs1VMQlhsgamQwAAAhQ"]
[Mon Jun 15 20:17:10.930109 2026] [security2:error] [pid 51003:tid 51031] [remote 47.128.122.124:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.smgl.org"] [uri "/product/sterling-silver-bracelets-wholesale/cab-stone-bracelets/aqua-chalcedony-with-blue-topaz-vintage-925-sterling-silver-bracelet/"] [unique_id "ajCyJspsKyvb75pkSvaMTwAB2hs"]
[Mon Jun 15 20:17:10.931959 2026] [security2:error] [pid 53359:tid 53551] [client 43.172.194.80:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "studioforge.in"] [uri "/index.php"] [unique_id "ajCyJvC2Xs1VMQlhsgamPQAAAkw"]
[Mon Jun 15 20:17:10.937566 2026] [security2:error] [pid 53359:tid 53561] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/include/"] [unique_id "ajCyJvC2Xs1VMQlhsgamTAAAAlY"]
[Mon Jun 15 20:17:10.944077 2026] [security2:error] [pid 51003:tid 51021] [remote 107.172.26.151:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.smgl.org"] [uri "/product-category/wholesale-sterling-silver-rings/prong-setting-rings-rings/"] [unique_id "ajCyJspsKyvb75pkSvaMUQAB5hE"], referer: https://www.smgl.org/
[Mon Jun 15 20:17:10.993083 2026] [security2:error] [pid 53359:tid 53534] [client 142.248.80.164:62984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "webdisk.mikaan.in"] [uri "/___proxy_subdomain_webdisk/.env.production.copy"] [unique_id "ajCyJvC2Xs1VMQlhsgamTgAAAjs"]
[Mon Jun 15 20:17:11.018515 2026] [security2:error] [pid 53359:tid 53604] [client 82.102.18.118:55566] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-content/plugins/wordpress-seo/"] [unique_id "ajCyJ_C2Xs1VMQlhsgamUgAAAoE"]
[Mon Jun 15 20:17:11.061020 2026] [security2:error] [pid 53359:tid 53573] [client 66.249.68.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.samanvaycommunications.com"] [uri "/index.php"] [unique_id "ajCyJ_C2Xs1VMQlhsgamTwAAAmI"]
[Mon Jun 15 20:17:11.105238 2026] [security2:error] [pid 51003:tid 51169] [client 175.0.59.152:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCyJspsKyvb75pkSvaMTAABs04"]
[Mon Jun 15 20:17:11.156679 2026] [security2:error] [pid 53359:tid 53598] [client 103.125.146.76:28049] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/log.php"] [unique_id "ajCyJ_C2Xs1VMQlhsgamXAAAAns"]
[Mon Jun 15 20:17:11.214463 2026] [security2:error] [pid 53359:tid 53603] [client 114.119.156.227:49207] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "koyeldasguptanaha.com"] [uri "/"] [unique_id "ajCyJ_C2Xs1VMQlhsgamYwAAAoA"], referer: https://koyeldasguptanaha.com/
[Mon Jun 15 20:17:11.214586 2026] [security2:error] [pid 53359:tid 53575] [client 85.204.70.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyJ_C2Xs1VMQlhsgamWwAAAmQ"]
[Mon Jun 15 20:17:11.214604 2026] [security2:error] [pid 53359:tid 53575] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyJ_C2Xs1VMQlhsgamWwAAAmQ"]
[Mon Jun 15 20:17:11.216426 2026] [security2:error] [pid 53359:tid 53541] [client 85.204.70.112:38918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/include/"] [unique_id "ajCyJ_C2Xs1VMQlhsgamVwAAAkI"]
[Mon Jun 15 20:17:11.226407 2026] [security2:error] [pid 51003:tid 51154] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-content/plugins/wordpress-seo/index.php"] [unique_id "ajCyJ8psKyvb75pkSvaMWQAAAaQ"]
[Mon Jun 15 20:17:11.229125 2026] [security2:error] [pid 53359:tid 53572] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-content/plugins/wordpress-seo/"] [unique_id "ajCyJ_C2Xs1VMQlhsgamXQAAAmE"]
[Mon Jun 15 20:17:11.256829 2026] [security2:error] [pid 51003:tid 51233] [client 31.219.209.201:63671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.209.219.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCyJ8psKyvb75pkSvaMWwAAAfM"]
[Mon Jun 15 20:17:11.256978 2026] [security2:error] [pid 51003:tid 51233] [client 31.219.209.201:63671] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCyJ8psKyvb75pkSvaMWwAAAfM"]
[Mon Jun 15 20:17:11.275520 2026] [security2:error] [pid 53359:tid 53585] [client 95.108.213.192:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyJ_C2Xs1VMQlhsgamZQAAAm4"]
[Mon Jun 15 20:17:11.277668 2026] [security2:error] [pid 53359:tid 53559] [client 95.108.213.192:34776] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyJ_C2Xs1VMQlhsgamYQACVGs"]
[Mon Jun 15 20:17:11.277703 2026] [security2:error] [pid 51003:tid 51160] [client 113.162.24.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCyJspsKyvb75pkSvaMUgABqkI"]
[Mon Jun 15 20:17:11.300388 2026] [security2:error] [pid 51003:tid 51020] [remote 213.171.208.62:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.208.171.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "travelmax.in"] [uri "/wp-login.php"] [unique_id "ajCyJ8psKyvb75pkSvaMXQAB9RA"], referer: https://travelmax.in/wp-login.php
[Mon Jun 15 20:17:11.378245 2026] [security2:error] [pid 53359:tid 53599] [client 82.102.18.118:55566] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/js/"] [unique_id "ajCyJ_C2Xs1VMQlhsgamaAAAAnw"]
[Mon Jun 15 20:17:11.407223 2026] [security2:error] [pid 53359:tid 53548] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/Assets/"] [unique_id "ajCyJ_C2Xs1VMQlhsgamawAAAkk"]
[Mon Jun 15 20:17:11.541028 2026] [security2:error] [pid 53359:tid 53610] [client 103.125.146.39:43073] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/css/dist/components/"] [unique_id "ajCyJ_C2Xs1VMQlhsgamcQAAAoc"]
[Mon Jun 15 20:17:11.675578 2026] [security2:error] [pid 53359:tid 53504] [client 85.204.70.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyJ_C2Xs1VMQlhsgamdQAAAh0"]
[Mon Jun 15 20:17:11.675615 2026] [security2:error] [pid 53359:tid 53504] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyJ_C2Xs1VMQlhsgamdQAAAh0"]
[Mon Jun 15 20:17:11.692032 2026] [security2:error] [pid 53359:tid 53509] [client 85.204.70.112:38918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/Assets/"] [unique_id "ajCyJ_C2Xs1VMQlhsgamcAAAAiI"]
[Mon Jun 15 20:17:11.822158 2026] [security2:error] [pid 53359:tid 53606] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/images/stories/"] [unique_id "ajCyJ_C2Xs1VMQlhsgamewAAAoM"]
[Mon Jun 15 20:17:11.832759 2026] [security2:error] [pid 53359:tid 53497] [client 82.102.18.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyJ_C2Xs1VMQlhsgamdAAAAhY"]
[Mon Jun 15 20:17:11.832782 2026] [security2:error] [pid 53359:tid 53497] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyJ_C2Xs1VMQlhsgamdAAAAhY"]
[Mon Jun 15 20:17:11.870165 2026] [security2:error] [pid 53359:tid 53615] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/js/"] [unique_id "ajCyJ_C2Xs1VMQlhsgambQAAAow"]
[Mon Jun 15 20:17:11.949767 2026] [security2:error] [pid 53359:tid 53605] [client 103.125.146.71:34107] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/ID3/"] [unique_id "ajCyJ_C2Xs1VMQlhsgamgAAAAoI"]
[Mon Jun 15 20:17:11.955067 2026] [security2:error] [pid 53359:tid 53554] [client 114.119.140.214:27609] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mycoimbatore.com"] [uri "/blog/low-carb-indian-diet-plan-for-losing-weight"] [unique_id "ajCyJ_C2Xs1VMQlhsgamggAAAk8"], referer: http://mycoimbatore.com/blog/low-carb-indian-diet-plan-for-losing-weight
[Mon Jun 15 20:17:12.021693 2026] [security2:error] [pid 53359:tid 53507] [client 82.102.18.118:55566] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-content/plugins/woocommerce/assets/js/"] [unique_id "ajCyKPC2Xs1VMQlhsgamhwAAAiA"]
[Mon Jun 15 20:17:12.079097 2026] [rewrite:error] [pid 53359:tid 53409] [remote 47.79.197.22:37742] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:17:12.156571 2026] [security2:error] [pid 53359:tid 53517] [client 85.204.70.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyKPC2Xs1VMQlhsgamiQAAAio"]
[Mon Jun 15 20:17:12.156607 2026] [security2:error] [pid 53359:tid 53517] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyKPC2Xs1VMQlhsgamiQAAAio"]
[Mon Jun 15 20:17:12.160566 2026] [security2:error] [pid 53359:tid 53594] [client 85.204.70.112:38918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/images/stories/"] [unique_id "ajCyJ_C2Xs1VMQlhsgamhQAAAnc"]
[Mon Jun 15 20:17:12.243036 2026] [security2:error] [pid 53359:tid 53457] [remote 74.7.242.32:58322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.242.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "my-eyezzy.webiknows.net"] [uri "/vendor/magnific-popup/vendor/magnific-popup/images/main-banner/images/testimonials/css/images/main-banner/js/shap/background/js/doctor/index.php"] [unique_id "ajCyKPC2Xs1VMQlhsgamkgACkVs"], referer: https://my-eyezzy.webiknows.net/vendor/magnific-popup/vendor/magnific-popup/images/main-banner/images/testimonials/css/images/main-banner/js/shap/background/js/functions.js
[Mon Jun 15 20:17:12.249547 2026] [security2:error] [pid 53359:tid 53500] [client 43.173.174.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCyJ_C2Xs1VMQlhsgamfwACGU4"]
[Mon Jun 15 20:17:12.269402 2026] [security2:error] [pid 53359:tid 53607] [client 43.173.173.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCyJ_C2Xs1VMQlhsgamhAAChGg"]
[Mon Jun 15 20:17:12.299350 2026] [security2:error] [pid 53359:tid 53582] [client 47.79.207.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "db.geeksinsight.com"] [uri "/index.php"] [unique_id "ajCyKPC2Xs1VMQlhsgamkwAAAms"], referer: https://www.google.com/
[Mon Jun 15 20:17:12.303837 2026] [security2:error] [pid 53359:tid 53568] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/plugins/"] [unique_id "ajCyKPC2Xs1VMQlhsgamlgAAAl0"]
[Mon Jun 15 20:17:12.310225 2026] [security2:error] [pid 51003:tid 51197] [client 111.119.175.99:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kthemani.com"] [uri "/index.php"] [unique_id "ajCyJspsKyvb75pkSvaMQgABzxc"]
[Mon Jun 15 20:17:12.333512 2026] [rewrite:error] [pid 53359:tid 53454] [remote 47.79.197.22:37742] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:17:12.341958 2026] [security2:error] [pid 51003:tid 51243] [client 65.111.30.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.procrastinatingworker.imcorp.in"] [uri "/index.php"] [unique_id "ajCyKMpsKyvb75pkSvaMbQAAAf0"]
[Mon Jun 15 20:17:12.369291 2026] [security2:error] [pid 53359:tid 53496] [client 103.125.146.48:59031] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/bolt.php"] [unique_id "ajCyKPC2Xs1VMQlhsgammwAAAhU"]
[Mon Jun 15 20:17:12.399526 2026] [security2:error] [pid 53359:tid 53475] [remote 154.17.113.121:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.smgl.org"] [uri "/"] [unique_id "ajCyKPC2Xs1VMQlhsgamnAACSW0"]
[Mon Jun 15 20:17:12.446160 2026] [security2:error] [pid 53359:tid 53563] [client 82.102.18.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyKPC2Xs1VMQlhsgamjwAAAlg"]
[Mon Jun 15 20:17:12.446185 2026] [security2:error] [pid 53359:tid 53563] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyKPC2Xs1VMQlhsgamjwAAAlg"]
[Mon Jun 15 20:17:12.446182 2026] [security2:error] [pid 53359:tid 53599] [client 57.141.14.28:60986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyKPC2Xs1VMQlhsgammQACfC4"]
[Mon Jun 15 20:17:12.468528 2026] [security2:error] [pid 51003:tid 51194] [client 213.180.203.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyKMpsKyvb75pkSvaMcwAAAcw"]
[Mon Jun 15 20:17:12.498887 2026] [security2:error] [pid 53359:tid 53498] [client 213.180.203.9:51126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyKPC2Xs1VMQlhsgamlwACF1E"]
[Mon Jun 15 20:17:12.506241 2026] [security2:error] [pid 53359:tid 53570] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-content/plugins/woocommerce/assets/js/"] [unique_id "ajCyKPC2Xs1VMQlhsgamjQAAAl8"]
[Mon Jun 15 20:17:12.618512 2026] [security2:error] [pid 53359:tid 53609] [client 85.204.70.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyKPC2Xs1VMQlhsgampAAAAoY"]
[Mon Jun 15 20:17:12.618546 2026] [security2:error] [pid 53359:tid 53609] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyKPC2Xs1VMQlhsgampAAAAoY"]
[Mon Jun 15 20:17:12.622106 2026] [security2:error] [pid 53359:tid 53566] [client 85.204.70.112:38918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/plugins/"] [unique_id "ajCyKPC2Xs1VMQlhsgamogAAAls"]
[Mon Jun 15 20:17:12.657282 2026] [security2:error] [pid 53359:tid 53558] [client 82.102.18.118:55566] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-content/plugins/woocommerce/"] [unique_id "ajCyKPC2Xs1VMQlhsgampwAAAlM"]
[Mon Jun 15 20:17:12.801661 2026] [security2:error] [pid 53359:tid 53539] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/php/"] [unique_id "ajCyKPC2Xs1VMQlhsgamrAAAAkA"]
[Mon Jun 15 20:17:12.816045 2026] [security2:error] [pid 53359:tid 53590] [client 103.125.146.69:34247] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content.php"] [unique_id "ajCyKPC2Xs1VMQlhsgamrwAAAnM"]
[Mon Jun 15 20:17:13.074303 2026] [security2:error] [pid 53359:tid 53507] [client 82.102.18.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyKPC2Xs1VMQlhsgamsgAAAiA"]
[Mon Jun 15 20:17:13.074332 2026] [security2:error] [pid 53359:tid 53507] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyKPC2Xs1VMQlhsgamsgAAAiA"]
[Mon Jun 15 20:17:13.102426 2026] [security2:error] [pid 53359:tid 53552] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-content/plugins/woocommerce/"] [unique_id "ajCyKPC2Xs1VMQlhsgamrgAAAk0"]
[Mon Jun 15 20:17:13.149981 2026] [security2:error] [pid 53359:tid 53541] [client 85.204.70.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyKPC2Xs1VMQlhsgamvAAAAkI"]
[Mon Jun 15 20:17:13.150006 2026] [security2:error] [pid 53359:tid 53541] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyKPC2Xs1VMQlhsgamvAAAAkI"]
[Mon Jun 15 20:17:13.169006 2026] [security2:error] [pid 53359:tid 53555] [client 85.204.70.112:38918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/php/"] [unique_id "ajCyKPC2Xs1VMQlhsgamuwAAAlA"]
[Mon Jun 15 20:17:13.173256 2026] [security2:error] [pid 51003:tid 51181] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "travelmax.in"] [uri "/wp-login.php"] [unique_id "ajCyKcpsKyvb75pkSvaMgwABvyQ"], referer: https://travelmax.shellming.workers.dev
[Mon Jun 15 20:17:13.270696 2026] [security2:error] [pid 53359:tid 53371] [remote 154.17.113.121:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.smgl.org"] [uri "/product-category/wholesale-sterling-silver-rings/prong-setting-rings-rings/"] [unique_id "ajCyKfC2Xs1VMQlhsgamwQACXQU"], referer: https://www.smgl.org/
[Mon Jun 15 20:17:13.279177 2026] [security2:error] [pid 51003:tid 51147] [client 103.125.146.56:34503] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/xmlrpc.php"] [unique_id "ajCyKcpsKyvb75pkSvaMhgAAAZ0"]
[Mon Jun 15 20:17:13.304557 2026] [security2:error] [pid 53359:tid 53557] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/wp-admin/css/"] [unique_id "ajCyKfC2Xs1VMQlhsgamxQAAAlI"]
[Mon Jun 15 20:17:13.373587 2026] [security2:error] [pid 51003:tid 51208] [client 47.79.207.128:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "societytodaynews.com"] [uri "/index.php"] [unique_id "ajCyKcpsKyvb75pkSvaMhQAAAdo"], referer: https://www.google.com/
[Mon Jun 15 20:17:13.398350 2026] [security2:error] [pid 51003:tid 51159] [client 114.119.152.33:57363] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "audiomart.in"] [uri "/product-category/headphones"] [unique_id "ajCyKcpsKyvb75pkSvaMiwAAAak"], referer: https://audiomart.in/product-category/headphones
[Mon Jun 15 20:17:13.468129 2026] [security2:error] [pid 53359:tid 53550] [client 82.102.18.118:55566] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-admin/meta/"] [unique_id "ajCyKfC2Xs1VMQlhsgam0wAAAks"]
[Mon Jun 15 20:17:13.485417 2026] [autoindex:error] [pid 53359:tid 53498] [client 85.204.70.112:38918] AH01276: Cannot serve directory /home4/dreamsta/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:17:13.486081 2026] [security2:error] [pid 53359:tid 53498] [client 85.204.70.112:38918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "geekjuggernaut.com"] [uri "/wp-admin/css/"] [unique_id "ajCyKfC2Xs1VMQlhsgamzQAAAhc"]
[Mon Jun 15 20:17:13.538966 2026] [security2:error] [pid 53359:tid 53514] [client 87.250.224.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyKfC2Xs1VMQlhsgam1wAAAic"]
[Mon Jun 15 20:17:13.540722 2026] [security2:error] [pid 53359:tid 53602] [client 87.250.224.132:52200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyKfC2Xs1VMQlhsgam1QACf3s"]
[Mon Jun 15 20:17:13.602078 2026] [security2:error] [pid 51003:tid 51162] [client 142.248.80.164:47896] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webdisk.mikaan.in"] [uri "/___proxy_subdomain_webdisk/.env.production.swp"] [unique_id "ajCyKcpsKyvb75pkSvaMjwAAAaw"]
[Mon Jun 15 20:17:13.602109 2026] [security2:error] [pid 53359:tid 53621] [client 142.248.80.164:47804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webdisk.mikaan.in"] [uri "/___proxy_subdomain_webdisk/.env.local.swp"] [unique_id "ajCyKfC2Xs1VMQlhsgam3AAAApI"]
[Mon Jun 15 20:17:13.605583 2026] [security2:error] [pid 51003:tid 51235] [client 142.248.80.164:47866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webdisk.mikaan.in"] [uri "/___proxy_subdomain_webdisk/.env.production.backup"] [unique_id "ajCyKcpsKyvb75pkSvaMkgAAAfU"]
[Mon Jun 15 20:17:13.609504 2026] [security2:error] [pid 51003:tid 51205] [client 142.248.80.164:47802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webdisk.mikaan.in"] [uri "/___proxy_subdomain_webdisk/.env.local~"] [unique_id "ajCyKcpsKyvb75pkSvaMkwAAAdc"]
[Mon Jun 15 20:17:13.609538 2026] [security2:error] [pid 53359:tid 53525] [client 142.248.80.164:47770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "webdisk.mikaan.in"] [uri "/___proxy_subdomain_webdisk/.env.copy"] [unique_id "ajCyKfC2Xs1VMQlhsgam3gAAAjI"]
[Mon Jun 15 20:17:13.610189 2026] [security2:error] [pid 53359:tid 53604] [client 142.248.80.164:47774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webdisk.mikaan.in"] [uri "/___proxy_subdomain_webdisk/.env.local.bak"] [unique_id "ajCyKfC2Xs1VMQlhsgam3wAAAoE"]
[Mon Jun 15 20:17:13.612348 2026] [security2:error] [pid 53359:tid 53590] [client 142.248.80.164:47776] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webdisk.mikaan.in"] [uri "/___proxy_subdomain_webdisk/.env.local.old"] [unique_id "ajCyKfC2Xs1VMQlhsgam4QAAAnM"]
[Mon Jun 15 20:17:13.616608 2026] [security2:error] [pid 53359:tid 53587] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/wp-content/themes/twentytwenty/"] [unique_id "ajCyKfC2Xs1VMQlhsgam4gAAAnA"]
[Mon Jun 15 20:17:13.675696 2026] [security2:error] [pid 53359:tid 53546] [client 103.125.146.44:58587] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wa/"] [unique_id "ajCyKfC2Xs1VMQlhsgam5wAAAkc"]
[Mon Jun 15 20:17:13.704974 2026] [security2:error] [pid 53359:tid 53561] [client 34.91.100.6:57344] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.stylecredits.com"] [uri "/"] [unique_id "ajCyKfC2Xs1VMQlhsgam6QAAAlY"]
[Mon Jun 15 20:17:13.705059 2026] [security2:error] [pid 53359:tid 53561] [client 34.91.100.6:57344] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cpcontacts.stylecredits.com"] [uri "/"] [unique_id "ajCyKfC2Xs1VMQlhsgam6QAAAlY"]
[Mon Jun 15 20:17:13.786989 2026] [security2:error] [pid 51003:tid 51219] [client 57.141.14.61:30372] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyKcpsKyvb75pkSvaMlgAB5UA"]
[Mon Jun 15 20:17:13.868191 2026] [security2:error] [pid 53359:tid 53605] [client 82.102.18.118:47714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyKfC2Xs1VMQlhsgam5AAAAoI"]
[Mon Jun 15 20:17:13.868217 2026] [security2:error] [pid 53359:tid 53605] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/index.php"] [unique_id "ajCyKfC2Xs1VMQlhsgam5AAAAoI"]
[Mon Jun 15 20:17:13.904123 2026] [security2:error] [pid 53359:tid 53572] [client 85.204.70.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyKfC2Xs1VMQlhsgam7wAAAmE"]
[Mon Jun 15 20:17:13.904154 2026] [security2:error] [pid 53359:tid 53572] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyKfC2Xs1VMQlhsgam7wAAAmE"]
[Mon Jun 15 20:17:13.915022 2026] [security2:error] [pid 53359:tid 53536] [client 85.204.70.112:38918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/wp-content/themes/twentytwenty/"] [unique_id "ajCyKfC2Xs1VMQlhsgam7AAAAj0"]
[Mon Jun 15 20:17:14.022174 2026] [security2:error] [pid 53359:tid 53451] [remote 43.173.179.124:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCyKfC2Xs1VMQlhsgam2gACfFU"], referer: https://mywordsnthoughts.com/useful-tips-for-your-family-trips/
[Mon Jun 15 20:17:14.023224 2026] [security2:error] [pid 53359:tid 53521] [client 82.102.18.118:55566] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-admin/network/"] [unique_id "ajCyKvC2Xs1VMQlhsganAQAAAi4"]
[Mon Jun 15 20:17:14.077616 2026] [security2:error] [pid 53359:tid 53426] [remote 43.172.194.176:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCyKfC2Xs1VMQlhsgam4wACaTw"], referer: https://mywordsnthoughts.com/useful-tips-for-your-family-trips/
[Mon Jun 15 20:17:14.093234 2026] [security2:error] [pid 53359:tid 53578] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/wp-content/cache/"] [unique_id "ajCyKvC2Xs1VMQlhsganBQAAAmc"]
[Mon Jun 15 20:17:14.111744 2026] [security2:error] [pid 51003:tid 51143] [client 103.125.146.39:52363] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/assets/"] [unique_id "ajCyKspsKyvb75pkSvaMowAAAZk"]
[Mon Jun 15 20:17:14.114794 2026] [security2:error] [pid 51003:tid 51257] [client 142.248.80.164:47802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webdisk.mikaan.in"] [uri "/___proxy_subdomain_webdisk/.env~"] [unique_id "ajCyKspsKyvb75pkSvaMpAAAAgs"]
[Mon Jun 15 20:17:14.114868 2026] [security2:error] [pid 51003:tid 51246] [client 142.248.80.164:47866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webdisk.mikaan.in"] [uri "/___proxy_subdomain_webdisk/.env.swp"] [unique_id "ajCyKspsKyvb75pkSvaMpgAAAgA"]
[Mon Jun 15 20:17:14.184143 2026] [rewrite:error] [pid 53359:tid 53381] [remote 47.79.199.59:37024] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:17:14.199350 2026] [security2:error] [pid 51003:tid 51171] [client 142.248.80.164:47728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "webdisk.mikaan.in"] [uri "/___proxy_subdomain_webdisk/.env.local.orig"] [unique_id "ajCyKspsKyvb75pkSvaMqAAAAbU"]
[Mon Jun 15 20:17:14.200288 2026] [security2:error] [pid 51003:tid 51245] [client 142.248.80.164:47896] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "webdisk.mikaan.in"] [uri "/___proxy_subdomain_webdisk/.env.orig"] [unique_id "ajCyKspsKyvb75pkSvaMqQAAAf8"]
[Mon Jun 15 20:17:14.200302 2026] [security2:error] [pid 53359:tid 53551] [client 142.248.80.164:47804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webdisk.mikaan.in"] [uri "/___proxy_subdomain_webdisk/.env.local.backup"] [unique_id "ajCyKvC2Xs1VMQlhsganCwAAAkw"]
[Mon Jun 15 20:17:14.360494 2026] [security2:error] [pid 53359:tid 53525] [client 85.204.70.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyKvC2Xs1VMQlhsganEQAAAjI"]
[Mon Jun 15 20:17:14.360532 2026] [security2:error] [pid 53359:tid 53525] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyKvC2Xs1VMQlhsganEQAAAjI"]
[Mon Jun 15 20:17:14.368165 2026] [security2:error] [pid 53359:tid 53601] [client 85.204.70.112:38918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/wp-content/cache/"] [unique_id "ajCyKvC2Xs1VMQlhsganDgAAAn4"]
[Mon Jun 15 20:17:14.415692 2026] [security2:error] [pid 53359:tid 53595] [client 142.248.80.164:47912] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "webdisk.mikaan.in"] [uri "/___proxy_subdomain_webdisk/.env.production.orig"] [unique_id "ajCyKvC2Xs1VMQlhsganGAAAAng"]
[Mon Jun 15 20:17:14.448213 2026] [rewrite:error] [pid 53359:tid 53367] [remote 47.79.199.59:37024] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:17:14.487613 2026] [security2:error] [pid 53359:tid 53495] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-admin/network/index.php"] [unique_id "ajCyKvC2Xs1VMQlhsganCgAAAhQ"]
[Mon Jun 15 20:17:14.491298 2026] [security2:error] [pid 51003:tid 51149] [client 149.102.234.4:58552] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.sanskratshlok.com"] [uri "/wp-login.php"] [unique_id "ajCyKspsKyvb75pkSvaMpwAAAZ8"]
[Mon Jun 15 20:17:14.497563 2026] [security2:error] [pid 51003:tid 51236] [client 142.248.80.164:47884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webdisk.mikaan.in"] [uri "/___proxy_subdomain_webdisk/.env.production~"] [unique_id "ajCyKspsKyvb75pkSvaMtQAAAfY"]
[Mon Jun 15 20:17:14.497563 2026] [security2:error] [pid 53359:tid 53522] [client 142.248.80.164:47842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webdisk.mikaan.in"] [uri "/___proxy_subdomain_webdisk/.env.production.bak"] [unique_id "ajCyKvC2Xs1VMQlhsganHwAAAi8"]
[Mon Jun 15 20:17:14.497852 2026] [security2:error] [pid 51003:tid 51216] [client 142.248.80.164:47826] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "webdisk.mikaan.in"] [uri "/___proxy_subdomain_webdisk/.env.local.copy"] [unique_id "ajCyKspsKyvb75pkSvaMtgAAAeI"]
[Mon Jun 15 20:17:14.503354 2026] [security2:error] [pid 53359:tid 53510] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/wp-admin/maint/"] [unique_id "ajCyKvC2Xs1VMQlhsganIAAAAiM"]
[Mon Jun 15 20:17:14.505611 2026] [security2:error] [pid 53359:tid 53598] [client 142.248.80.164:47856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webdisk.mikaan.in"] [uri "/___proxy_subdomain_webdisk/.env.production.old"] [unique_id "ajCyKvC2Xs1VMQlhsganIQAAAns"]
[Mon Jun 15 20:17:14.511702 2026] [security2:error] [pid 51003:tid 51260] [client 103.125.146.64:24893] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/themes/admin.php"] [unique_id "ajCyKspsKyvb75pkSvaMtwAAAg4"]
[Mon Jun 15 20:17:14.557459 2026] [security2:error] [pid 51003:tid 51243] [client 57.141.14.53:39844] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyKspsKyvb75pkSvaMsQAB_Tc"]
[Mon Jun 15 20:17:14.617007 2026] [security2:error] [pid 53359:tid 53423] [remote 206.232.122.200:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.smgl.org"] [uri "/"] [unique_id "ajCyKvC2Xs1VMQlhsganJgACazk"], referer: http://www.baidu.org/
[Mon Jun 15 20:17:14.634799 2026] [security2:error] [pid 53359:tid 53577] [client 82.102.18.118:47714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-login.php"] [unique_id "ajCyKvC2Xs1VMQlhsganJwAAAmY"]
[Mon Jun 15 20:17:14.634959 2026] [security2:error] [pid 53359:tid 53577] [client 82.102.18.118:47714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-login.php"] [unique_id "ajCyKvC2Xs1VMQlhsganJwAAAmY"]
[Mon Jun 15 20:17:14.681590 2026] [security2:error] [pid 51003:tid 51215] [client 213.180.203.244:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyKspsKyvb75pkSvaMvAAAAeE"]
[Mon Jun 15 20:17:14.692850 2026] [security2:error] [pid 53359:tid 53561] [client 213.180.203.244:35384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyKvC2Xs1VMQlhsganJAACVj4"]
[Mon Jun 15 20:17:14.714665 2026] [autoindex:error] [pid 53359:tid 53553] [client 85.204.70.112:38918] AH01276: Cannot serve directory /home4/dreamsta/public_html/wp-admin/maint/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:17:14.715465 2026] [security2:error] [pid 53359:tid 53553] [client 85.204.70.112:38918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "geekjuggernaut.com"] [uri "/wp-admin/maint/"] [unique_id "ajCyKvC2Xs1VMQlhsganKAAAAk4"]
[Mon Jun 15 20:17:14.786317 2026] [security2:error] [pid 53359:tid 53531] [client 82.102.18.118:55566] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-admin/user/"] [unique_id "ajCyKvC2Xs1VMQlhsganKgAAAjg"]
[Mon Jun 15 20:17:14.810154 2026] [rewrite:error] [pid 53359:tid 53618] [client 47.79.197.234:25220] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:17:14.847205 2026] [security2:error] [pid 53359:tid 53521] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/wp-content/plugins/akismet/"] [unique_id "ajCyKvC2Xs1VMQlhsganLgAAAi4"]
[Mon Jun 15 20:17:14.893283 2026] [security2:error] [pid 53359:tid 53523] [client 103.125.146.50:57977] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/plugins/enhanced-text-widget/analyst/src/403x.php"] [unique_id "ajCyKvC2Xs1VMQlhsganMgAAAjA"]
[Mon Jun 15 20:17:14.965994 2026] [security2:error] [pid 53359:tid 53386] [remote 43.173.179.197:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCyKvC2Xs1VMQlhsganHAACkhQ"], referer: https://mywordsnthoughts.com/mahalakshmi-iyer-top-10-bollywood-songs-of-my-choice/
[Mon Jun 15 20:17:14.970206 2026] [security2:error] [pid 53359:tid 53390] [remote 43.172.196.237:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCyKvC2Xs1VMQlhsganHQACgRg"], referer: https://mywordsnthoughts.com/mahalakshmi-iyer-top-10-bollywood-songs-of-my-choice/
[Mon Jun 15 20:17:15.050034 2026] [authz_core:error] [pid 53359:tid 53612] [client 85.204.70.112:0] AH01630: client denied by server configuration: /home4/dreamsta/public_html/wp-content/plugins/akismet/
[Mon Jun 15 20:17:15.051684 2026] [security2:error] [pid 53359:tid 53612] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCyK_C2Xs1VMQlhsganNgAAAok"]
[Mon Jun 15 20:17:15.054234 2026] [security2:error] [pid 53359:tid 53498] [client 85.204.70.112:38918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "geekjuggernaut.com"] [uri "/wp-content/plugins/akismet/"] [unique_id "ajCyKvC2Xs1VMQlhsganNQAAAhc"]
[Mon Jun 15 20:17:15.074246 2026] [security2:error] [pid 51003:tid 51138] [client 65.111.30.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.procrastinatingworker.imcorp.in"] [uri "/index.php"] [unique_id "ajCyKspsKyvb75pkSvaMvwAAAZQ"]
[Mon Jun 15 20:17:15.079180 2026] [security2:error] [pid 51003:tid 51152] [client 43.173.179.202:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCyKspsKyvb75pkSvaMuQABokE"], referer: https://mywordsnthoughts.com/top-20-bollywood-duets-composed-by-anu-malik/
[Mon Jun 15 20:17:15.080534 2026] [security2:error] [pid 53359:tid 53500] [client 47.79.201.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "techemporia.com"] [uri "/index.php"] [unique_id "ajCyKfC2Xs1VMQlhsgam9QAAAhk"], referer: https://www.google.com/
[Mon Jun 15 20:17:15.136129 2026] [security2:error] [pid 53359:tid 53398] [remote 43.173.181.93:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCyKvC2Xs1VMQlhsganKQACVCA"], referer: https://mywordsnthoughts.com/top-20-bollywood-duets-composed-by-anu-malik/
[Mon Jun 15 20:17:15.199122 2026] [security2:error] [pid 53359:tid 53545] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/wp-includes/assets/"] [unique_id "ajCyK_C2Xs1VMQlhsganOgAAAkY"]
[Mon Jun 15 20:17:15.268178 2026] [rewrite:error] [pid 53359:tid 53554] [client 47.79.197.234:25220] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:17:15.310872 2026] [security2:error] [pid 53359:tid 53525] [client 103.125.146.54:51319] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-admin/includes/"] [unique_id "ajCyK_C2Xs1VMQlhsganQAAAAjI"]
[Mon Jun 15 20:17:15.450086 2026] [autoindex:error] [pid 53359:tid 53594] [client 85.204.70.112:0] AH01276: Cannot serve directory /home4/dreamsta/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:17:15.450642 2026] [security2:error] [pid 53359:tid 53594] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCyK_C2Xs1VMQlhsganSQAAAnc"]
[Mon Jun 15 20:17:15.453373 2026] [security2:error] [pid 53359:tid 53573] [client 85.204.70.112:38918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "geekjuggernaut.com"] [uri "/wp-includes/assets/"] [unique_id "ajCyK_C2Xs1VMQlhsganQgAAAmI"]
[Mon Jun 15 20:17:15.478771 2026] [security2:error] [pid 53359:tid 53406] [remote 206.232.122.200:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.smgl.org"] [uri "/product-category/wholesale-sterling-silver-rings/prong-setting-rings-rings/"] [unique_id "ajCyK_C2Xs1VMQlhsganSwACeCg"], referer: https://www.smgl.org/
[Mon Jun 15 20:17:15.546889 2026] [security2:error] [pid 53359:tid 53537] [client 82.102.18.118:52554] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-admin/user/index.php"] [unique_id "ajCyK_C2Xs1VMQlhsganPAAAAj4"]
[Mon Jun 15 20:17:15.599630 2026] [security2:error] [pid 53359:tid 53552] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/wp-includes/block-patterns/"] [unique_id "ajCyK_C2Xs1VMQlhsganWgAAAk0"]
[Mon Jun 15 20:17:15.722474 2026] [security2:error] [pid 53359:tid 53557] [client 82.102.18.118:52554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-login.php"] [unique_id "ajCyK_C2Xs1VMQlhsganXQAAAlI"]
[Mon Jun 15 20:17:15.722596 2026] [security2:error] [pid 53359:tid 53557] [client 82.102.18.118:52554] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-login.php"] [unique_id "ajCyK_C2Xs1VMQlhsganXQAAAlI"]
[Mon Jun 15 20:17:15.724299 2026] [security2:error] [pid 51003:tid 51233] [client 202.58.78.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kthemani.com"] [uri "/index.php"] [unique_id "ajCyKcpsKyvb75pkSvaMmwAB800"]
[Mon Jun 15 20:17:15.738210 2026] [security2:error] [pid 51003:tid 51144] [client 95.108.213.136:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyK8psKyvb75pkSvaMzwAAAZo"]
[Mon Jun 15 20:17:15.773812 2026] [security2:error] [pid 51003:tid 51139] [client 95.108.213.136:45000] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyK8psKyvb75pkSvaMzQABlQE"]
[Mon Jun 15 20:17:15.802987 2026] [autoindex:error] [pid 53359:tid 53622] [client 85.204.70.112:0] AH01276: Cannot serve directory /home4/dreamsta/public_html/wp-includes/block-patterns/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:17:15.803418 2026] [security2:error] [pid 53359:tid 53622] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCyK_C2Xs1VMQlhsganbQAAApM"]
[Mon Jun 15 20:17:15.806205 2026] [security2:error] [pid 53359:tid 53496] [client 85.204.70.112:38918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "geekjuggernaut.com"] [uri "/wp-includes/block-patterns/"] [unique_id "ajCyK_C2Xs1VMQlhsganYAAAAhU"]
[Mon Jun 15 20:17:15.874188 2026] [security2:error] [pid 53359:tid 53505] [client 82.102.18.118:55566] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-content/"] [unique_id "ajCyK_C2Xs1VMQlhsganbwAAAh4"]
[Mon Jun 15 20:17:15.936056 2026] [security2:error] [pid 53359:tid 53523] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/wp-includes/block-supports/"] [unique_id "ajCyK_C2Xs1VMQlhsgancgAAAjA"]
[Mon Jun 15 20:17:15.936593 2026] [security2:error] [pid 53359:tid 53578] [client 74.119.118.205:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.diggysguide.com"] [uri "/index.php"] [unique_id "ajCyK_C2Xs1VMQlhsgancQAAAmc"]
[Mon Jun 15 20:17:15.940055 2026] [security2:error] [pid 51003:tid 51190] [client 74.119.118.205:34641] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.diggysguide.com"] [uri "/atlantis/atlantean-hospital"] [unique_id "ajCyK8psKyvb75pkSvaM1AAAAcg"]
[Mon Jun 15 20:17:16.097245 2026] [rewrite:error] [pid 53359:tid 53471] [remote 47.79.197.240:27018] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:17:16.144087 2026] [autoindex:error] [pid 53359:tid 53608] [client 85.204.70.112:0] AH01276: Cannot serve directory /home4/dreamsta/public_html/wp-includes/block-supports/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:17:16.144528 2026] [security2:error] [pid 53359:tid 53608] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCyLPC2Xs1VMQlhsgangAAAAoU"]
[Mon Jun 15 20:17:16.192893 2026] [security2:error] [pid 53359:tid 53591] [client 85.204.70.112:38918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "geekjuggernaut.com"] [uri "/wp-includes/block-supports/"] [unique_id "ajCyLPC2Xs1VMQlhsganfQAAAnQ"]
[Mon Jun 15 20:17:16.217661 2026] [security2:error] [pid 51003:tid 51077] [remote 157.55.39.58:11044] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ybsolutions.in"] [uri "/index.php"] [unique_id "ajCyLMpsKyvb75pkSvaM3wACBkk"]
[Mon Jun 15 20:17:16.338780 2026] [security2:error] [pid 53359:tid 53597] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/wp-includes/html-api/"] [unique_id "ajCyLPC2Xs1VMQlhsganggAAAno"]
[Mon Jun 15 20:17:16.381073 2026] [rewrite:error] [pid 53359:tid 53378] [remote 47.79.197.240:27018] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:17:16.503423 2026] [security2:error] [pid 53359:tid 53554] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-content/index.php"] [unique_id "ajCyLPC2Xs1VMQlhsganiAAAAk8"]
[Mon Jun 15 20:17:16.511216 2026] [security2:error] [pid 53359:tid 53514] [client 82.102.18.118:52584] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-content/"] [unique_id "ajCyLPC2Xs1VMQlhsgangwAAAic"]
[Mon Jun 15 20:17:16.541932 2026] [autoindex:error] [pid 53359:tid 53517] [client 85.204.70.112:0] AH01276: Cannot serve directory /home4/dreamsta/public_html/wp-includes/html-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:17:16.542451 2026] [security2:error] [pid 53359:tid 53517] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCyLPC2Xs1VMQlhsganiwAAAio"]
[Mon Jun 15 20:17:16.546510 2026] [security2:error] [pid 53359:tid 53503] [client 85.204.70.112:38918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "geekjuggernaut.com"] [uri "/wp-includes/html-api/"] [unique_id "ajCyLPC2Xs1VMQlhsganiQAAAhw"]
[Mon Jun 15 20:17:16.568672 2026] [security2:error] [pid 51003:tid 51185] [client 157.55.39.58:11044] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ybsolutions.in"] [uri "/index.php"] [unique_id "ajCyLMpsKyvb75pkSvaM4wABw14"]
[Mon Jun 15 20:17:16.663518 2026] [security2:error] [pid 53359:tid 53572] [client 82.102.18.118:55566] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-content/plugins/"] [unique_id "ajCyLPC2Xs1VMQlhsganjQAAAmE"]
[Mon Jun 15 20:17:16.699334 2026] [security2:error] [pid 53359:tid 53600] [client 49.47.129.38:34836] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gpgaya.org"] [uri "/Admin/index.php"] [unique_id "ajCyK_C2Xs1VMQlhsganbAACfUU"], referer: https://www.gpgaya.org/
[Mon Jun 15 20:17:16.703384 2026] [security2:error] [pid 53359:tid 53577] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/wp-includes/js/"] [unique_id "ajCyLPC2Xs1VMQlhsgankgAAAmY"]
[Mon Jun 15 20:17:16.704934 2026] [security2:error] [pid 51003:tid 51106] [remote 74.7.227.149:53822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.shreeramsweets-co-in.xgh.ggk.mybluehostin.me"] [uri "/images/plugins/rangeslider/images_scroller/js/index.php"] [unique_id "ajCyLMpsKyvb75pkSvaM5QABuWY"], referer: https://www.shreeramsweets-co-in.xgh.ggk.mybluehostin.me/images/plugins/rangeslider/images_scroller/js/jquery.min.js
[Mon Jun 15 20:17:16.706547 2026] [security2:error] [pid 53359:tid 53600] [client 49.47.129.38:34836] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gpgaya.org"] [uri "/index.php"] [unique_id "ajCyLPC2Xs1VMQlhsgankQACfQ4"], referer: https://gpgaya.org/assets/lib/owl-carousel/owl-carousel.css
[Mon Jun 15 20:17:16.715151 2026] [security2:error] [pid 53359:tid 53557] [client 103.125.146.37:30831] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/plugins/ssss/src.php"] [unique_id "ajCyLPC2Xs1VMQlhsgankwAAAlI"]
[Mon Jun 15 20:17:16.802008 2026] [security2:error] [pid 53359:tid 53590] [client 192.140.64.94:29772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.64.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCyLPC2Xs1VMQlhsganlwAAAnM"]
[Mon Jun 15 20:17:16.802223 2026] [security2:error] [pid 53359:tid 53590] [client 192.140.64.94:29772] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCyLPC2Xs1VMQlhsganlwAAAnM"]
[Mon Jun 15 20:17:16.864015 2026] [security2:error] [pid 51003:tid 51181] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-content/plugins/index.php"] [unique_id "ajCyLMpsKyvb75pkSvaM7QAAAb8"]
[Mon Jun 15 20:17:16.866484 2026] [security2:error] [pid 53359:tid 53622] [client 82.102.18.118:52584] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-content/plugins/"] [unique_id "ajCyLPC2Xs1VMQlhsganmAAAApM"]
[Mon Jun 15 20:17:16.886108 2026] [autoindex:error] [pid 53359:tid 53615] [client 85.204.70.112:0] AH01276: Cannot serve directory /home4/dreamsta/public_html/wp-includes/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:17:16.886838 2026] [security2:error] [pid 53359:tid 53615] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCyLPC2Xs1VMQlhsgannAAAAow"]
[Mon Jun 15 20:17:16.889452 2026] [security2:error] [pid 53359:tid 53526] [client 85.204.70.112:38918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "geekjuggernaut.com"] [uri "/wp-includes/js/"] [unique_id "ajCyLPC2Xs1VMQlhsganmgAAAjM"]
[Mon Jun 15 20:17:16.999449 2026] [security2:error] [pid 53359:tid 53521] [client 57.141.14.73:49456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyLPC2Xs1VMQlhsgannQACLhY"]
[Mon Jun 15 20:17:17.021797 2026] [security2:error] [pid 53359:tid 53520] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/wp-includes/php-compat/"] [unique_id "ajCyLfC2Xs1VMQlhsganpQAAAi0"]
[Mon Jun 15 20:17:17.034821 2026] [security2:error] [pid 53359:tid 53574] [client 82.102.18.118:55566] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-content/themes/"] [unique_id "ajCyLfC2Xs1VMQlhsganpgAAAmM"]
[Mon Jun 15 20:17:17.102009 2026] [security2:error] [pid 53359:tid 53500] [client 103.125.146.34:35151] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-admin/js/widgets/images/"] [unique_id "ajCyLfC2Xs1VMQlhsganqAAAAhk"]
[Mon Jun 15 20:17:17.191927 2026] [autoindex:error] [pid 51003:tid 51235] [client 85.204.70.112:0] AH01276: Cannot serve directory /home4/dreamsta/public_html/wp-includes/php-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:17:17.192408 2026] [security2:error] [pid 51003:tid 51235] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCyLcpsKyvb75pkSvaM-QAAAfU"]
[Mon Jun 15 20:17:17.194885 2026] [security2:error] [pid 53359:tid 53585] [client 85.204.70.112:38918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "geekjuggernaut.com"] [uri "/wp-includes/php-compat/"] [unique_id "ajCyLfC2Xs1VMQlhsganqQAAAm4"]
[Mon Jun 15 20:17:17.222101 2026] [security2:error] [pid 53359:tid 53550] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-content/themes/index.php"] [unique_id "ajCyLfC2Xs1VMQlhsganrgAAAks"]
[Mon Jun 15 20:17:17.226158 2026] [security2:error] [pid 53359:tid 53593] [client 82.102.18.118:52584] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-content/themes/"] [unique_id "ajCyLfC2Xs1VMQlhsganqwAAAnY"]
[Mon Jun 15 20:17:17.232491 2026] [security2:error] [pid 53359:tid 53372] [remote 107.173.151.220:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.smgl.org"] [uri "/product-category/wholesale-sterling-silver-rings/prong-setting-rings-rings/"] [unique_id "ajCyLfC2Xs1VMQlhsganrwACVQY"], referer: https://www.smgl.org/
[Mon Jun 15 20:17:17.274533 2026] [security2:error] [pid 51003:tid 51055] [remote 78.46.92.235:47076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.92.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "greenspacearchitecture.com"] [uri "/wp-login.php"] [unique_id "ajCyLcpsKyvb75pkSvaM-wAB6zM"]
[Mon Jun 15 20:17:17.330586 2026] [security2:error] [pid 53359:tid 53554] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/wp-includes/PHPMailer/"] [unique_id "ajCyLfC2Xs1VMQlhsgansgAAAk8"]
[Mon Jun 15 20:17:17.379639 2026] [security2:error] [pid 53359:tid 53573] [client 82.102.18.118:55566] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-admin/includes/"] [unique_id "ajCyLfC2Xs1VMQlhsgantAAAAmI"]
[Mon Jun 15 20:17:17.470804 2026] [security2:error] [pid 51003:tid 51119] [remote 78.46.92.235:47076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.92.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "greenspacearchitecture.com"] [uri "/wp-login.php"] [unique_id "ajCyLcpsKyvb75pkSvaM_gABlXM"], referer: https://greenspacearchitecture.com/wp-login.php
[Mon Jun 15 20:17:17.485105 2026] [security2:error] [pid 51003:tid 51153] [client 103.125.146.33:53137] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/Text/"] [unique_id "ajCyLcpsKyvb75pkSvaNAAAAAaM"]
[Mon Jun 15 20:17:17.509478 2026] [security2:error] [pid 53359:tid 53598] [client 145.239.10.137:47294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.10.239.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kthemani.com"] [uri "/license_docs316.php"] [unique_id "ajCyLfC2Xs1VMQlhsgantwAAAns"], referer: http://kthemani.com/license_docs316.php
[Mon Jun 15 20:17:17.521420 2026] [autoindex:error] [pid 51003:tid 51143] [client 85.204.70.112:0] AH01276: Cannot serve directory /home4/dreamsta/public_html/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:17:17.521931 2026] [security2:error] [pid 51003:tid 51143] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCyLcpsKyvb75pkSvaNAgAAAZk"]
[Mon Jun 15 20:17:17.581061 2026] [autoindex:error] [pid 53359:tid 53620] [client 82.102.18.118:52584] AH01276: Cannot serve directory /home3/itjbthmy/public_html/jcpenneysurvey1/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:17:17.581735 2026] [security2:error] [pid 53359:tid 53620] [client 82.102.18.118:52584] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-admin/includes/"] [unique_id "ajCyLfC2Xs1VMQlhsganvQAAApE"]
[Mon Jun 15 20:17:17.604051 2026] [security2:error] [pid 53359:tid 53503] [client 85.204.70.112:38918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "geekjuggernaut.com"] [uri "/wp-includes/PHPMailer/"] [unique_id "ajCyLfC2Xs1VMQlhsganuAAAAhw"]
[Mon Jun 15 20:17:17.618055 2026] [security2:error] [pid 53359:tid 53533] [client 57.141.14.106:20999] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyLfC2Xs1VMQlhsganvAACOhE"]
[Mon Jun 15 20:17:17.733098 2026] [security2:error] [pid 53359:tid 53532] [client 82.102.18.118:55566] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-admin/"] [unique_id "ajCyLfC2Xs1VMQlhsganwgAAAjk"]
[Mon Jun 15 20:17:17.817945 2026] [security2:error] [pid 53359:tid 53618] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/wp-includes/pomo/"] [unique_id "ajCyLfC2Xs1VMQlhsganxQAAAo8"]
[Mon Jun 15 20:17:17.916035 2026] [security2:error] [pid 53359:tid 53588] [client 103.125.146.52:60217] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/packed.php"] [unique_id "ajCyLfC2Xs1VMQlhsganxwAAAnE"]
[Mon Jun 15 20:17:18.024825 2026] [autoindex:error] [pid 53359:tid 53604] [client 85.204.70.112:0] AH01276: Cannot serve directory /home4/dreamsta/public_html/wp-includes/pomo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:17:18.025316 2026] [security2:error] [pid 53359:tid 53604] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCyLvC2Xs1VMQlhsganzwAAAoE"]
[Mon Jun 15 20:17:18.028172 2026] [security2:error] [pid 53359:tid 53613] [client 85.204.70.112:38918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "geekjuggernaut.com"] [uri "/wp-includes/pomo/"] [unique_id "ajCyLfC2Xs1VMQlhsganzQAAAoo"]
[Mon Jun 15 20:17:18.057513 2026] [security2:error] [pid 53359:tid 53563] [client 65.111.30.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.procrastinatingworker.imcorp.in"] [uri "/index.php"] [unique_id "ajCyLfC2Xs1VMQlhsganzAAAAlg"]
[Mon Jun 15 20:17:18.087143 2026] [security2:error] [pid 53359:tid 53444] [remote 47.128.122.124:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.smgl.org"] [uri "/wp-content/plugins/woocommerce/assets/css/photoswipe/photoswipe.min.css"] [unique_id "ajCyLvC2Xs1VMQlhsgan2AACVE4"], referer: https://www.smgl.org/product/sterling-silver-bracelets-wholesale/cab-stone-bracelets/aqua-chalcedony-with-blue-topaz-vintage-925-sterling-silver-bracelet/
[Mon Jun 15 20:17:18.089666 2026] [security2:error] [pid 53359:tid 53457] [remote 176.61.149.165:47372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.149.61.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenordesignsllc.info"] [uri "/wp-login.php"] [unique_id "ajCyLvC2Xs1VMQlhsgan1wACk1s"]
[Mon Jun 15 20:17:18.136547 2026] [security2:error] [pid 53359:tid 53404] [remote 43.173.175.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.175.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mywordsnthoughts.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ajCyLvC2Xs1VMQlhsgan1AACSyY"], referer: https://mywordsnthoughts.com/mahalakshmi-iyer-top-10-bollywood-songs-of-my-choice/
[Mon Jun 15 20:17:18.138241 2026] [security2:error] [pid 53359:tid 53459] [remote 47.128.122.124:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.smgl.org"] [uri "/wp-content/plugins/js_composer/assets/lib/bower/font-awesome/css/font-awesome.min.css"] [unique_id "ajCyLvC2Xs1VMQlhsgan3AACJl0"], referer: https://www.smgl.org/product/sterling-silver-bracelets-wholesale/cab-stone-bracelets/aqua-chalcedony-with-blue-topaz-vintage-925-sterling-silver-bracelet/
[Mon Jun 15 20:17:18.138242 2026] [security2:error] [pid 53359:tid 53470] [remote 47.128.122.124:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.smgl.org"] [uri "/wp-includes/css/dist/block-library/style.min.css"] [unique_id "ajCyLvC2Xs1VMQlhsgan2QACM2g"], referer: https://www.smgl.org/product/sterling-silver-bracelets-wholesale/cab-stone-bracelets/aqua-chalcedony-with-blue-topaz-vintage-925-sterling-silver-bracelet/
[Mon Jun 15 20:17:18.142274 2026] [security2:error] [pid 53359:tid 53455] [remote 47.128.122.124:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.smgl.org"] [uri "/wp-content/plugins/woocommerce/assets/css/photoswipe/default-skin/default-skin.min.css"] [unique_id "ajCyLvC2Xs1VMQlhsgan4QACSVk"], referer: https://www.smgl.org/product/sterling-silver-bracelets-wholesale/cab-stone-bracelets/aqua-chalcedony-with-blue-topaz-vintage-925-sterling-silver-bracelet/
[Mon Jun 15 20:17:18.150198 2026] [security2:error] [pid 53359:tid 53447] [remote 47.128.122.124:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.smgl.org"] [uri "/wp-content/themes/wdjewelry/css/font-awesome.min.css"] [unique_id "ajCyLvC2Xs1VMQlhsgan4wACLlE"], referer: https://www.smgl.org/product/sterling-silver-bracelets-wholesale/cab-stone-bracelets/aqua-chalcedony-with-blue-topaz-vintage-925-sterling-silver-bracelet/
[Mon Jun 15 20:17:18.155210 2026] [security2:error] [pid 53359:tid 53420] [remote 47.128.122.124:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.122.128.47.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.smgl.org"] [uri "/wp-content/cache/autoptimize/autoptimize_single_ad2744c2cec1da79171b1833333e4b20.php"] [unique_id "ajCyLvC2Xs1VMQlhsgan3QACQTY"], referer: https://www.smgl.org/product/sterling-silver-bracelets-wholesale/cab-stone-bracelets/aqua-chalcedony-with-blue-topaz-vintage-925-sterling-silver-bracelet/
[Mon Jun 15 20:17:18.158772 2026] [security2:error] [pid 53359:tid 53446] [remote 47.128.122.124:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.122.128.47.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.smgl.org"] [uri "/wp-content/cache/autoptimize/autoptimize_single_6cea3c0d6def902f4f75becc551082c1.php"] [unique_id "ajCyLvC2Xs1VMQlhsgan5AACLVA"], referer: https://www.smgl.org/product/sterling-silver-bracelets-wholesale/cab-stone-bracelets/aqua-chalcedony-with-blue-topaz-vintage-925-sterling-silver-bracelet/
[Mon Jun 15 20:17:18.161941 2026] [security2:error] [pid 53359:tid 53463] [remote 47.128.122.124:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.122.128.47.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.smgl.org"] [uri "/wp-content/cache/autoptimize/autoptimize_single_1f9769c84c381114ab8622acb616a1ce.php"] [unique_id "ajCyLvC2Xs1VMQlhsgan5QACY2E"], referer: https://www.smgl.org/product/sterling-silver-bracelets-wholesale/cab-stone-bracelets/aqua-chalcedony-with-blue-topaz-vintage-925-sterling-silver-bracelet/
[Mon Jun 15 20:17:18.162230 2026] [security2:error] [pid 53359:tid 53424] [remote 47.128.122.124:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.122.128.47.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.smgl.org"] [uri "/wp-content/cache/autoptimize/autoptimize_single_9cc03c1823f3b429584ce7860b61e4c4.php"] [unique_id "ajCyLvC2Xs1VMQlhsgan5gACfDo"], referer: https://www.smgl.org/product/sterling-silver-bracelets-wholesale/cab-stone-bracelets/aqua-chalcedony-with-blue-topaz-vintage-925-sterling-silver-bracelet/
[Mon Jun 15 20:17:18.163850 2026] [security2:error] [pid 53359:tid 53418] [remote 47.128.122.124:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.122.128.47.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.smgl.org"] [uri "/wp-content/cache/autoptimize/autoptimize_single_dffa98f57dd7b06714f57d224f336c10.php"] [unique_id "ajCyLvC2Xs1VMQlhsgan5wACjTQ"], referer: https://www.smgl.org/product/sterling-silver-bracelets-wholesale/cab-stone-bracelets/aqua-chalcedony-with-blue-topaz-vintage-925-sterling-silver-bracelet/
[Mon Jun 15 20:17:18.165354 2026] [security2:error] [pid 53359:tid 53419] [remote 47.128.122.124:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.122.128.47.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.smgl.org"] [uri "/wp-content/cache/autoptimize/autoptimize_single_09e7f42b71c205c0cba8abe9e95176bd.php"] [unique_id "ajCyLvC2Xs1VMQlhsgan6AACezU"], referer: https://www.smgl.org/product/sterling-silver-bracelets-wholesale/cab-stone-bracelets/aqua-chalcedony-with-blue-topaz-vintage-925-sterling-silver-bracelet/
[Mon Jun 15 20:17:18.166656 2026] [security2:error] [pid 51003:tid 51102] [remote 47.128.122.124:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.122.128.47.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.smgl.org"] [uri "/wp-content/cache/autoptimize/autoptimize_single_59d266c0ea580aae1113acb3761f7ad5.php"] [unique_id "ajCyLspsKyvb75pkSvaNEgABoGI"], referer: https://www.smgl.org/product/sterling-silver-bracelets-wholesale/cab-stone-bracelets/aqua-chalcedony-with-blue-topaz-vintage-925-sterling-silver-bracelet/
[Mon Jun 15 20:17:18.167738 2026] [security2:error] [pid 53359:tid 53502] [client 82.102.18.118:52584] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-admin/index.php"] [unique_id "ajCyLfC2Xs1VMQlhsganxgAAAhs"]
[Mon Jun 15 20:17:18.169613 2026] [security2:error] [pid 53359:tid 53477] [remote 47.128.122.124:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.122.128.47.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.smgl.org"] [uri "/wp-content/cache/autoptimize/autoptimize_single_e98f5279cacaef826050eb2595082e77.php"] [unique_id "ajCyLvC2Xs1VMQlhsgan6wACkm8"], referer: https://www.smgl.org/product/sterling-silver-bracelets-wholesale/cab-stone-bracelets/aqua-chalcedony-with-blue-topaz-vintage-925-sterling-silver-bracelet/
[Mon Jun 15 20:17:18.170358 2026] [security2:error] [pid 53359:tid 53476] [remote 47.128.122.124:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.122.128.47.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.smgl.org"] [uri "/wp-content/cache/autoptimize/autoptimize_single_3d1cf842c8413a7007fce03336f8202c.php"] [unique_id "ajCyLvC2Xs1VMQlhsgan7AACN24"], referer: https://www.smgl.org/product/sterling-silver-bracelets-wholesale/cab-stone-bracelets/aqua-chalcedony-with-blue-topaz-vintage-925-sterling-silver-bracelet/
[Mon Jun 15 20:17:18.170763 2026] [security2:error] [pid 53359:tid 53454] [remote 47.128.122.124:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.122.128.47.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.smgl.org"] [uri "/wp-content/cache/autoptimize/autoptimize_single_f4efa2eb70333fb2760635e38818fa13.php"] [unique_id "ajCyLvC2Xs1VMQlhsgan2gACMFg"], referer: https://www.smgl.org/product/sterling-silver-bracelets-wholesale/cab-stone-bracelets/aqua-chalcedony-with-blue-topaz-vintage-925-sterling-silver-bracelet/
[Mon Jun 15 20:17:18.171504 2026] [security2:error] [pid 53359:tid 53475] [remote 47.128.122.124:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.122.128.47.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.smgl.org"] [uri "/wp-content/cache/autoptimize/autoptimize_single_fca867690dd857e4475f31fd0184171c.php"] [unique_id "ajCyLvC2Xs1VMQlhsgan2wACa20"], referer: https://www.smgl.org/product/sterling-silver-bracelets-wholesale/cab-stone-bracelets/aqua-chalcedony-with-blue-topaz-vintage-925-sterling-silver-bracelet/
[Mon Jun 15 20:17:18.173877 2026] [security2:error] [pid 51003:tid 51084] [remote 47.128.122.124:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.122.128.47.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.smgl.org"] [uri "/wp-content/cache/autoptimize/autoptimize_single_be939de447621cb2ce0e839174b845b2.php"] [unique_id "ajCyLspsKyvb75pkSvaNDwABmFA"], referer: https://www.smgl.org/product/sterling-silver-bracelets-wholesale/cab-stone-bracelets/aqua-chalcedony-with-blue-topaz-vintage-925-sterling-silver-bracelet/
[Mon Jun 15 20:17:18.176917 2026] [security2:error] [pid 53359:tid 53452] [remote 47.128.122.124:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.122.128.47.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.smgl.org"] [uri "/wp-content/cache/autoptimize/autoptimize_single_e6273d3972e0cc3ecdee941ad28d1607.php"] [unique_id "ajCyLvC2Xs1VMQlhsgan7QACFlY"], referer: https://www.smgl.org/product/sterling-silver-bracelets-wholesale/cab-stone-bracelets/aqua-chalcedony-with-blue-topaz-vintage-925-sterling-silver-bracelet/
[Mon Jun 15 20:17:18.177896 2026] [security2:error] [pid 51003:tid 51042] [remote 47.128.122.124:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.122.128.47.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.smgl.org"] [uri "/wp-content/cache/autoptimize/autoptimize_single_d49fbfc6c0444e7c67b2ee7ae284a293.php"] [unique_id "ajCyLspsKyvb75pkSvaNEAAB1CY"], referer: https://www.smgl.org/product/sterling-silver-bracelets-wholesale/cab-stone-bracelets/aqua-chalcedony-with-blue-topaz-vintage-925-sterling-silver-bracelet/
[Mon Jun 15 20:17:18.177931 2026] [security2:error] [pid 53359:tid 53448] [remote 47.128.122.124:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.122.128.47.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.smgl.org"] [uri "/wp-content/cache/autoptimize/autoptimize_single_053cfa8d6ea1d89c5bf9229c1930d9a6.php"] [unique_id "ajCyLvC2Xs1VMQlhsgan3gACbFI"], referer: https://www.smgl.org/product/sterling-silver-bracelets-wholesale/cab-stone-bracelets/aqua-chalcedony-with-blue-topaz-vintage-925-sterling-silver-bracelet/
[Mon Jun 15 20:17:18.180299 2026] [security2:error] [pid 53359:tid 53412] [remote 47.128.122.124:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.122.128.47.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.smgl.org"] [uri "/wp-content/cache/autoptimize/autoptimize_single_8548adc0dc9b1069087b5e858d7577a2.php"] [unique_id "ajCyLvC2Xs1VMQlhsgan4AACYC4"], referer: https://www.smgl.org/product/sterling-silver-bracelets-wholesale/cab-stone-bracelets/aqua-chalcedony-with-blue-topaz-vintage-925-sterling-silver-bracelet/
[Mon Jun 15 20:17:18.182773 2026] [security2:error] [pid 53359:tid 53371] [remote 47.128.122.124:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.122.128.47.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.smgl.org"] [uri "/wp-content/cache/autoptimize/autoptimize_single_9dbd5ee0b28216428fe9b5cf90bed835.php"] [unique_id "ajCyLvC2Xs1VMQlhsgan7gACPQU"], referer: https://www.smgl.org/product/sterling-silver-bracelets-wholesale/cab-stone-bracelets/aqua-chalcedony-with-blue-topaz-vintage-925-sterling-silver-bracelet/
[Mon Jun 15 20:17:18.185164 2026] [security2:error] [pid 51003:tid 51006] [remote 47.128.122.124:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.122.128.47.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.smgl.org"] [uri "/wp-content/cache/autoptimize/autoptimize_single_a4c39e59fc71a1b57e15b4acb3df4c2b.php"] [unique_id "ajCyLspsKyvb75pkSvaNEwABkQI"], referer: https://www.smgl.org/product/sterling-silver-bracelets-wholesale/cab-stone-bracelets/aqua-chalcedony-with-blue-topaz-vintage-925-sterling-silver-bracelet/
[Mon Jun 15 20:17:18.189115 2026] [security2:error] [pid 53359:tid 53375] [remote 47.128.122.124:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.smgl.org"] [uri "/wp-content/plugins/ubermenu/pro/assets/css/ubermenu.min.css"] [unique_id "ajCyLvC2Xs1VMQlhsgan7wACVgk"], referer: https://www.smgl.org/product/sterling-silver-bracelets-wholesale/cab-stone-bracelets/aqua-chalcedony-with-blue-topaz-vintage-925-sterling-silver-bracelet/
[Mon Jun 15 20:17:18.191030 2026] [security2:error] [pid 53359:tid 53486] [remote 47.128.122.124:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.smgl.org"] [uri "/wp-content/plugins/ubermenu/assets/fontawesome/css/all.min.css"] [unique_id "ajCyLvC2Xs1VMQlhsgan8AACGXg"], referer: https://www.smgl.org/product/sterling-silver-bracelets-wholesale/cab-stone-bracelets/aqua-chalcedony-with-blue-topaz-vintage-925-sterling-silver-bracelet/
[Mon Jun 15 20:17:18.202599 2026] [security2:error] [pid 53359:tid 53579] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/wp-includes/random_compat/"] [unique_id "ajCyLvC2Xs1VMQlhsgan8gAAAmg"]
[Mon Jun 15 20:17:18.233782 2026] [security2:error] [pid 53359:tid 53490] [remote 66.249.70.160:0] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.smgl.org"] [uri "/robots.txt"] [unique_id "ajCyLvC2Xs1VMQlhsgan8wACSHw"]
[Mon Jun 15 20:17:18.311154 2026] [security2:error] [pid 53359:tid 53401] [remote 47.128.122.124:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.122.128.47.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.smgl.org"] [uri "/wp-content/cache/autoptimize/autoptimize_single_e2d671c403c7e2bd09b3b298c748d0db.php"] [unique_id "ajCyLvC2Xs1VMQlhsgan-QACMiM"], referer: https://www.smgl.org/product/sterling-silver-bracelets-wholesale/cab-stone-bracelets/aqua-chalcedony-with-blue-topaz-vintage-925-sterling-silver-bracelet/
[Mon Jun 15 20:17:18.317946 2026] [security2:error] [pid 53359:tid 53376] [remote 47.128.122.124:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.122.128.47.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.smgl.org"] [uri "/wp-content/cache/autoptimize/autoptimize_single_f74840e67907a19167f227572d127b67.php"] [unique_id "ajCyLvC2Xs1VMQlhsgan-wACTgo"], referer: https://www.smgl.org/product/sterling-silver-bracelets-wholesale/cab-stone-bracelets/aqua-chalcedony-with-blue-topaz-vintage-925-sterling-silver-bracelet/
[Mon Jun 15 20:17:18.319869 2026] [security2:error] [pid 53359:tid 53492] [remote 47.128.122.124:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.122.128.47.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.smgl.org"] [uri "/wp-content/cache/autoptimize/autoptimize_single_29b36b02e1e619cffe2c0e8a3d3b73d5.php"] [unique_id "ajCyLvC2Xs1VMQlhsgan_QACj34"], referer: https://www.smgl.org/product/sterling-silver-bracelets-wholesale/cab-stone-bracelets/aqua-chalcedony-with-blue-topaz-vintage-925-sterling-silver-bracelet/
[Mon Jun 15 20:17:18.319889 2026] [security2:error] [pid 53359:tid 53369] [remote 47.128.122.124:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.122.128.47.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.smgl.org"] [uri "/wp-content/cache/autoptimize/autoptimize_single_8603fd0f67260e4e152c0dcb8f719109.php"] [unique_id "ajCyLvC2Xs1VMQlhsgan_AACTwM"], referer: https://www.smgl.org/product/sterling-silver-bracelets-wholesale/cab-stone-bracelets/aqua-chalcedony-with-blue-topaz-vintage-925-sterling-silver-bracelet/
[Mon Jun 15 20:17:18.324680 2026] [security2:error] [pid 53359:tid 53489] [remote 47.128.122.124:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.122.128.47.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.smgl.org"] [uri "/wp-content/cache/autoptimize/autoptimize_single_90e37bc52586fd4510bc2419e6df60dc.php"] [unique_id "ajCyLvC2Xs1VMQlhsgan_gACgXs"], referer: https://www.smgl.org/product/sterling-silver-bracelets-wholesale/cab-stone-bracelets/aqua-chalcedony-with-blue-topaz-vintage-925-sterling-silver-bracelet/
[Mon Jun 15 20:17:18.326494 2026] [security2:error] [pid 53359:tid 53485] [remote 111.225.149.243:33374] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "sports-window.com"] [uri "/"] [unique_id "ajCyLvC2Xs1VMQlhsgan_wACWXc"]
[Mon Jun 15 20:17:18.329154 2026] [security2:error] [pid 53359:tid 53481] [remote 176.61.149.165:47372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.149.61.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenordesignsllc.info"] [uri "/wp-login.php"] [unique_id "ajCyLvC2Xs1VMQlhsgan-gACTHM"], referer: https://jenordesignsllc.info/wp-login.php
[Mon Jun 15 20:17:18.331109 2026] [security2:error] [pid 53359:tid 53613] [client 82.102.18.118:52584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-login.php"] [unique_id "ajCyLvC2Xs1VMQlhsgaoAQAAAoo"]
[Mon Jun 15 20:17:18.331174 2026] [security2:error] [pid 53359:tid 53613] [client 82.102.18.118:52584] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-login.php"] [unique_id "ajCyLvC2Xs1VMQlhsgaoAQAAAoo"]
[Mon Jun 15 20:17:18.337992 2026] [security2:error] [pid 53359:tid 53566] [client 103.125.146.59:51319] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/ioxi-o.php"] [unique_id "ajCyLvC2Xs1VMQlhsgaoAwAAAls"]
[Mon Jun 15 20:17:18.397395 2026] [rewrite:error] [pid 53359:tid 53437] [remote 47.79.197.36:47386] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:17:18.428360 2026] [security2:error] [pid 53359:tid 53568] [client 85.204.70.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyLvC2Xs1VMQlhsgaoBAAAAl0"]
[Mon Jun 15 20:17:18.428382 2026] [security2:error] [pid 53359:tid 53568] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyLvC2Xs1VMQlhsgaoBAAAAl0"]
[Mon Jun 15 20:17:18.438718 2026] [security2:error] [pid 53359:tid 53555] [client 85.204.70.112:38918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/wp-includes/random_compat/"] [unique_id "ajCyLvC2Xs1VMQlhsgaoAAAAAlA"]
[Mon Jun 15 20:17:18.484953 2026] [security2:error] [pid 53359:tid 53521] [client 82.102.18.118:55566] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-content/upgrade/"] [unique_id "ajCyLvC2Xs1VMQlhsgaoCQAAAi4"]
[Mon Jun 15 20:17:18.597381 2026] [security2:error] [pid 53359:tid 53546] [client 196.176.247.111:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kthemani.com"] [uri "/index.php"] [unique_id "ajCyLPC2Xs1VMQlhsganhwAAAkc"]
[Mon Jun 15 20:17:18.599411 2026] [security2:error] [pid 53359:tid 53582] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/wp-includes/rest-api/"] [unique_id "ajCyLvC2Xs1VMQlhsgaoDwAAAms"]
[Mon Jun 15 20:17:18.601396 2026] [security2:error] [pid 53359:tid 53507] [client 110.249.201.139:41030] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mail.webiknows.com"] [uri "/robots.txt"] [unique_id "ajCyLvC2Xs1VMQlhsgaoEAAAAiA"]
[Mon Jun 15 20:17:18.659585 2026] [rewrite:error] [pid 53359:tid 53366] [remote 47.79.197.36:47386] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:17:18.735675 2026] [security2:error] [pid 51003:tid 51183] [client 103.125.146.47:65337] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/x.php"] [unique_id "ajCyLspsKyvb75pkSvaNHQAAAcE"]
[Mon Jun 15 20:17:18.774192 2026] [autoindex:error] [pid 53359:tid 53533] [client 85.204.70.112:0] AH01276: Cannot serve directory /home4/dreamsta/public_html/wp-includes/rest-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:17:18.774722 2026] [security2:error] [pid 53359:tid 53533] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCyLvC2Xs1VMQlhsgaoGQAAAjo"]
[Mon Jun 15 20:17:18.776664 2026] [security2:error] [pid 53359:tid 53558] [client 85.204.70.112:38918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "geekjuggernaut.com"] [uri "/wp-includes/rest-api/"] [unique_id "ajCyLvC2Xs1VMQlhsgaoFwAAAlM"]
[Mon Jun 15 20:17:18.907203 2026] [security2:error] [pid 53359:tid 53495] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/wp-includes/sitemaps/"] [unique_id "ajCyLvC2Xs1VMQlhsgaoGwAAAhQ"]
[Mon Jun 15 20:17:18.972784 2026] [autoindex:error] [pid 53359:tid 53532] [client 82.102.18.118:0] AH01276: Cannot serve directory /home3/itjbthmy/public_html/jcpenneysurvey1/wp-content/upgrade/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:17:18.973333 2026] [security2:error] [pid 53359:tid 53532] [client 82.102.18.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCyLvC2Xs1VMQlhsgaoHgAAAjk"]
[Mon Jun 15 20:17:18.975273 2026] [security2:error] [pid 53359:tid 53605] [client 82.102.18.118:54796] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.jcpenneysurvey.survey-survey.com"] [uri "/wp-content/upgrade/"] [unique_id "ajCyLvC2Xs1VMQlhsgaoHAAAAoI"]
[Mon Jun 15 20:17:19.022183 2026] [security2:error] [pid 53359:tid 53604] [client 43.173.179.73:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "itdeed.com"] [uri "/demomahayogini/product-tag/black-magic-removal-ontario"] [unique_id "ajCyL_C2Xs1VMQlhsgaoIgAAAoE"]
[Mon Jun 15 20:17:19.072868 2026] [security2:error] [pid 53359:tid 53585] [client 103.125.146.67:47279] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/languages/themes/"] [unique_id "ajCyL_C2Xs1VMQlhsgaoKgAAAm4"]
[Mon Jun 15 20:17:19.081726 2026] [security2:error] [pid 53359:tid 53491] [remote 107.175.16.62:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.smgl.org"] [uri "/product-category/wholesale-sterling-silver-rings/prong-setting-rings-rings/"] [unique_id "ajCyL_C2Xs1VMQlhsgaoKwACen0"], referer: https://www.smgl.org/
[Mon Jun 15 20:17:19.083747 2026] [autoindex:error] [pid 53359:tid 53614] [client 85.204.70.112:0] AH01276: Cannot serve directory /home4/dreamsta/public_html/wp-includes/sitemaps/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:17:19.084222 2026] [security2:error] [pid 53359:tid 53614] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCyL_C2Xs1VMQlhsgaoKQAAAos"]
[Mon Jun 15 20:17:19.090424 2026] [security2:error] [pid 53359:tid 53524] [client 85.204.70.112:38918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "geekjuggernaut.com"] [uri "/wp-includes/sitemaps/"] [unique_id "ajCyL_C2Xs1VMQlhsgaoJgAAAjE"]
[Mon Jun 15 20:17:19.224299 2026] [security2:error] [pid 53359:tid 53526] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/wp-includes/sodium_compat/"] [unique_id "ajCyL_C2Xs1VMQlhsgaoLwAAAjM"]
[Mon Jun 15 20:17:19.409570 2026] [security2:error] [pid 51003:tid 51170] [client 57.141.14.84:27404] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyL8psKyvb75pkSvaNKAABtCc"]
[Mon Jun 15 20:17:19.429477 2026] [autoindex:error] [pid 51003:tid 51224] [client 85.204.70.112:0] AH01276: Cannot serve directory /home4/dreamsta/public_html/wp-includes/sodium_compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:17:19.430014 2026] [security2:error] [pid 51003:tid 51224] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCyL8psKyvb75pkSvaNMwAAAeo"]
[Mon Jun 15 20:17:19.435275 2026] [security2:error] [pid 53359:tid 53517] [client 85.204.70.112:38918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "geekjuggernaut.com"] [uri "/wp-includes/sodium_compat/"] [unique_id "ajCyL_C2Xs1VMQlhsgaoMQAAAio"]
[Mon Jun 15 20:17:19.466878 2026] [security2:error] [pid 53359:tid 53422] [remote 183.83.134.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCyLvC2Xs1VMQlhsgaoHwACTzg"], referer: https://mywordsnthoughts.com/mounam-polum-madhuram-song-from-sagara-sangamam-lyrics-in-english-with-translation/
[Mon Jun 15 20:17:19.526124 2026] [security2:error] [pid 53359:tid 53599] [client 103.125.146.80:53585] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-file.php"] [unique_id "ajCyL_C2Xs1VMQlhsgaoMwAAAnw"]
[Mon Jun 15 20:17:19.580298 2026] [security2:error] [pid 51003:tid 51138] [client 183.83.134.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCyLspsKyvb75pkSvaNIAABlHc"], referer: https://mywordsnthoughts.com/mounam-polum-madhuram-song-from-sagara-sangamam-lyrics-in-english-with-translation/
[Mon Jun 15 20:17:19.605384 2026] [security2:error] [pid 53359:tid 53583] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/wp-includes/style-engine/"] [unique_id "ajCyL_C2Xs1VMQlhsgaoNgAAAmw"]
[Mon Jun 15 20:17:19.739898 2026] [security2:error] [pid 51003:tid 51235] [client 110.249.201.181:57012] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sports-window.com"] [uri "/robots.txt"] [unique_id "ajCyL8psKyvb75pkSvaNOQAAAfU"]
[Mon Jun 15 20:17:19.772724 2026] [security2:error] [pid 53359:tid 53460] [remote 185.55.229.75:53360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.229.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "divoniika.com"] [uri "/wp-login.php"] [unique_id "ajCyL_C2Xs1VMQlhsgaoOAACG14"]
[Mon Jun 15 20:17:19.800937 2026] [autoindex:error] [pid 51003:tid 51207] [client 85.204.70.112:0] AH01276: Cannot serve directory /home4/dreamsta/public_html/wp-includes/style-engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:17:19.801451 2026] [security2:error] [pid 51003:tid 51207] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCyL8psKyvb75pkSvaNPAAAAdk"]
[Mon Jun 15 20:17:19.805199 2026] [security2:error] [pid 53359:tid 53592] [client 85.204.70.112:38918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "geekjuggernaut.com"] [uri "/wp-includes/style-engine/"] [unique_id "ajCyL_C2Xs1VMQlhsgaoOQAAAnU"]
[Mon Jun 15 20:17:19.935070 2026] [security2:error] [pid 53359:tid 53542] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/wp-includes/theme-compat/"] [unique_id "ajCyL_C2Xs1VMQlhsgaoQwAAAkM"]
[Mon Jun 15 20:17:19.937371 2026] [security2:error] [pid 53359:tid 53519] [client 103.125.146.48:56571] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-wlx.php"] [unique_id "ajCyL_C2Xs1VMQlhsgaoRAAAAiw"]
[Mon Jun 15 20:17:20.003817 2026] [security2:error] [pid 53359:tid 53423] [remote 185.55.229.75:53360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.229.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "divoniika.com"] [uri "/wp-login.php"] [unique_id "ajCyL_C2Xs1VMQlhsgaoRgACcTk"], referer: https://divoniika.com/wp-login.php
[Mon Jun 15 20:17:20.131329 2026] [security2:error] [pid 51003:tid 51067] [remote 74.208.140.41:55824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.140.208.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.mizukicnc.com"] [uri "/wp-login.php"] [unique_id "ajCyMMpsKyvb75pkSvaNPwABnz8"]
[Mon Jun 15 20:17:20.145871 2026] [autoindex:error] [pid 51003:tid 51150] [client 85.204.70.112:0] AH01276: Cannot serve directory /home4/dreamsta/public_html/wp-includes/theme-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:17:20.146316 2026] [security2:error] [pid 51003:tid 51150] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCyMMpsKyvb75pkSvaNQAAAAaA"]
[Mon Jun 15 20:17:20.147897 2026] [security2:error] [pid 53359:tid 53498] [client 85.204.70.112:38918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "geekjuggernaut.com"] [uri "/wp-includes/theme-compat/"] [unique_id "ajCyMPC2Xs1VMQlhsgaoRwAAAhc"]
[Mon Jun 15 20:17:20.172788 2026] [security2:error] [pid 53359:tid 53537] [client 176.88.159.188:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kthemani.com"] [uri "/index.php"] [unique_id "ajCyLvC2Xs1VMQlhsgan6gAAAj4"]
[Mon Jun 15 20:17:20.306812 2026] [security2:error] [pid 53359:tid 53509] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/wp-includes/widgets/"] [unique_id "ajCyMPC2Xs1VMQlhsgaoTgAAAiI"]
[Mon Jun 15 20:17:20.319670 2026] [security2:error] [pid 51003:tid 51073] [remote 114.119.149.3:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mywordsnthoughts.com"] [uri "/myworld/vanitha-recipes/palak-puri"] [unique_id "ajCyMMpsKyvb75pkSvaNTAACB0U"], referer: https://mywordsnthoughts.com/myworld/vanitha-recipes/banana-puri/
[Mon Jun 15 20:17:20.324691 2026] [security2:error] [pid 53359:tid 53552] [client 43.172.196.247:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itdeed.com"] [uri "/demomahayogini/index.php"] [unique_id "ajCyL_C2Xs1VMQlhsgaoQAAAAk0"], referer: https://itdeed.com/demomahayogini/product-tag/black-magic-removal-ontario
[Mon Jun 15 20:17:20.411508 2026] [security2:error] [pid 53359:tid 53615] [client 103.125.146.51:41139] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-admin/maint/"] [unique_id "ajCyMPC2Xs1VMQlhsgaoUQAAAow"]
[Mon Jun 15 20:17:20.445514 2026] [security2:error] [pid 53359:tid 53597] [client 57.141.14.88:28486] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rohandasgupta.com"] [uri "/index.php"] [unique_id "ajCyMPC2Xs1VMQlhsgaoTAACej4"]
[Mon Jun 15 20:17:20.480605 2026] [autoindex:error] [pid 53359:tid 53520] [client 85.204.70.112:0] AH01276: Cannot serve directory /home4/dreamsta/public_html/wp-includes/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:17:20.481156 2026] [security2:error] [pid 53359:tid 53520] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCyMPC2Xs1VMQlhsgaoWAAAAi0"]
[Mon Jun 15 20:17:20.550506 2026] [rewrite:error] [pid 51003:tid 51111] [remote 47.79.198.222:7120] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:17:20.554169 2026] [security2:error] [pid 53359:tid 53612] [client 85.204.70.112:38918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "geekjuggernaut.com"] [uri "/wp-includes/widgets/"] [unique_id "ajCyMPC2Xs1VMQlhsgaoVAAAAok"]
[Mon Jun 15 20:17:20.590337 2026] [security2:error] [pid 51003:tid 51072] [remote 74.208.140.41:55824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.140.208.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.mizukicnc.com"] [uri "/wp-login.php"] [unique_id "ajCyMMpsKyvb75pkSvaNUQABv0Q"], referer: https://mail.mizukicnc.com/wp-login.php
[Mon Jun 15 20:17:20.703499 2026] [security2:error] [pid 53359:tid 53500] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/wp-admin/css/colors/ectoplasm/"] [unique_id "ajCyMPC2Xs1VMQlhsgaoXwAAAhk"]
[Mon Jun 15 20:17:20.763940 2026] [security2:error] [pid 53359:tid 53406] [remote 104.232.199.167:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.smgl.org"] [uri "/product-category/wholesale-sterling-silver-rings/prong-setting-rings-rings/"] [unique_id "ajCyMPC2Xs1VMQlhsgaoYgACLyg"], referer: https://www.smgl.org/
[Mon Jun 15 20:17:20.786734 2026] [security2:error] [pid 51003:tid 51147] [client 65.111.30.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.procrastinatingworker.imcorp.in"] [uri "/index.php"] [unique_id "ajCyMMpsKyvb75pkSvaNVgAAAZ0"]
[Mon Jun 15 20:17:20.819412 2026] [security2:error] [pid 51003:tid 51103] [remote 104.210.140.130:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.smgl.org"] [uri "/robots.txt"] [unique_id "ajCyMMpsKyvb75pkSvaNWwAB8mM"]
[Mon Jun 15 20:17:20.831452 2026] [security2:error] [pid 51003:tid 51255] [client 103.125.146.79:54847] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/blocks/archives/"] [unique_id "ajCyMMpsKyvb75pkSvaNXQAAAgk"]
[Mon Jun 15 20:17:20.835559 2026] [rewrite:error] [pid 51003:tid 51113] [remote 47.79.198.222:7120] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:17:20.890264 2026] [autoindex:error] [pid 53359:tid 53595] [client 85.204.70.112:38918] AH01276: Cannot serve directory /home4/dreamsta/public_html/wp-admin/css/colors/ectoplasm/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:17:20.890782 2026] [security2:error] [pid 53359:tid 53595] [client 85.204.70.112:38918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "geekjuggernaut.com"] [uri "/wp-admin/css/colors/ectoplasm/"] [unique_id "ajCyMPC2Xs1VMQlhsgaoZAAAAng"]
[Mon Jun 15 20:17:20.991628 2026] [security2:error] [pid 51003:tid 51168] [client 143.244.57.120:39900] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.surveylaya.com"] [uri "/wp-content/themes/"] [unique_id "ajCyMMpsKyvb75pkSvaNYgAAAbI"]
[Mon Jun 15 20:17:21.012312 2026] [security2:error] [pid 51003:tid 51014] [remote 57.141.14.44:26451] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyMMpsKyvb75pkSvaNYAABuwo"]
[Mon Jun 15 20:17:21.023640 2026] [security2:error] [pid 53359:tid 53519] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/wp-admin/css/colors/"] [unique_id "ajCyMfC2Xs1VMQlhsgaoZgAAAiw"]
[Mon Jun 15 20:17:21.254208 2026] [security2:error] [pid 51003:tid 51231] [client 103.125.146.54:33879] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/users.php"] [unique_id "ajCyMcpsKyvb75pkSvaNaQAAAfE"]
[Mon Jun 15 20:17:21.263214 2026] [autoindex:error] [pid 53359:tid 53618] [client 85.204.70.112:38918] AH01276: Cannot serve directory /home4/dreamsta/public_html/wp-admin/css/colors/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:17:21.263795 2026] [security2:error] [pid 53359:tid 53618] [client 85.204.70.112:38918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "geekjuggernaut.com"] [uri "/wp-admin/css/colors/"] [unique_id "ajCyMfC2Xs1VMQlhsgaobAAAAo8"]
[Mon Jun 15 20:17:21.403350 2026] [security2:error] [pid 53359:tid 53591] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/admin/images/slider/"] [unique_id "ajCyMfC2Xs1VMQlhsgaocQAAAnQ"]
[Mon Jun 15 20:17:21.642472 2026] [security2:error] [pid 51003:tid 51252] [client 85.204.70.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyMcpsKyvb75pkSvaNcAAAAgY"]
[Mon Jun 15 20:17:21.642502 2026] [security2:error] [pid 51003:tid 51252] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyMcpsKyvb75pkSvaNcAAAAgY"]
[Mon Jun 15 20:17:21.681476 2026] [security2:error] [pid 53359:tid 53622] [client 85.204.70.112:38918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/admin/images/slider/"] [unique_id "ajCyMfC2Xs1VMQlhsgaocwAAApM"]
[Mon Jun 15 20:17:21.695169 2026] [security2:error] [pid 51003:tid 51163] [client 103.125.146.37:37429] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/blocks/pullquote/"] [unique_id "ajCyMcpsKyvb75pkSvaNcwAAAa0"]
[Mon Jun 15 20:17:21.704002 2026] [security2:error] [pid 51003:tid 51164] [client 52.87.72.16:38350] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "audiomart.in"] [uri "/index.php"] [unique_id "ajCyL8psKyvb75pkSvaNJgAAAa4"], referer: https://audiomart.in/
[Mon Jun 15 20:17:21.704296 2026] [security2:error] [pid 53359:tid 53585] [client 162.214.80.21:33034] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "itdeed.com"] [uri "/demomahayogini/wp-cron.php"] [unique_id "ajCyMfC2Xs1VMQlhsgaodwAAAm4"]
[Mon Jun 15 20:17:21.816470 2026] [security2:error] [pid 53359:tid 53619] [client 85.204.70.112:59750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/admin/fckeditor/editor/filemanager/"] [unique_id "ajCyMfC2Xs1VMQlhsgaofAAAApA"]
[Mon Jun 15 20:17:21.822746 2026] [security2:error] [pid 51003:tid 51207] [client 31.219.209.201:64275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.209.219.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCyMcpsKyvb75pkSvaNdAAAAdk"]
[Mon Jun 15 20:17:21.822886 2026] [security2:error] [pid 51003:tid 51207] [client 31.219.209.201:64275] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCyMcpsKyvb75pkSvaNdAAAAdk"]
[Mon Jun 15 20:17:22.039665 2026] [security2:error] [pid 51003:tid 51029] [remote 43.172.198.43:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.198.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mywordsnthoughts.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ajCyMspsKyvb75pkSvaNgQAB8Bk"], referer: https://mywordsnthoughts.com/useful-tips-for-your-family-trips/
[Mon Jun 15 20:17:22.062111 2026] [security2:error] [pid 51003:tid 51158] [client 85.204.70.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyMcpsKyvb75pkSvaNfQAAAag"]
[Mon Jun 15 20:17:22.062139 2026] [security2:error] [pid 51003:tid 51158] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyMcpsKyvb75pkSvaNfQAAAag"]
[Mon Jun 15 20:17:22.065353 2026] [security2:error] [pid 53359:tid 53602] [client 85.204.70.112:38918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/admin/fckeditor/editor/filemanager/"] [unique_id "ajCyMfC2Xs1VMQlhsgaogQAAAn8"]
[Mon Jun 15 20:17:22.093485 2026] [security2:error] [pid 53359:tid 53554] [client 103.125.146.66:28689] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-admin.php"] [unique_id "ajCyMvC2Xs1VMQlhsgaohgAAAk8"]
[Mon Jun 15 20:17:22.176957 2026] [security2:error] [pid 51003:tid 51181] [client 2a03:2880:f806:43:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ruchini.hemani.finance"] [uri "/index.php"] [unique_id "ajCyMspsKyvb75pkSvaNggABv0A"]
[Mon Jun 15 20:17:22.339159 2026] [security2:error] [pid 51003:tid 51232] [client 85.204.70.112:40700] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/sites/default/files/"] [unique_id "ajCyMspsKyvb75pkSvaNhQAAAfI"]
[Mon Jun 15 20:17:22.393574 2026] [security2:error] [pid 53359:tid 53413] [remote 57.141.14.44:26459] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyMvC2Xs1VMQlhsgaoigACki8"]
[Mon Jun 15 20:17:22.527105 2026] [security2:error] [pid 53359:tid 53432] [remote 149.115.136.67:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.smgl.org"] [uri "/product-category/wholesale-sterling-silver-rings/prong-setting-rings-rings/"] [unique_id "ajCyMvC2Xs1VMQlhsgaokwACM0I"]
[Mon Jun 15 20:17:22.550013 2026] [security2:error] [pid 53359:tid 53518] [client 103.125.146.32:60241] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/files.php"] [unique_id "ajCyMvC2Xs1VMQlhsgaolAAAAis"]
[Mon Jun 15 20:17:22.598610 2026] [security2:error] [pid 53359:tid 53511] [client 213.180.203.155:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyMvC2Xs1VMQlhsgaolQAAAiQ"]
[Mon Jun 15 20:17:22.602832 2026] [security2:error] [pid 53359:tid 53558] [client 213.180.203.155:51332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyMvC2Xs1VMQlhsgaokAACU1c"]
[Mon Jun 15 20:17:22.652783 2026] [security2:error] [pid 53359:tid 53584] [client 85.204.70.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyMvC2Xs1VMQlhsgaolgAAAm0"]
[Mon Jun 15 20:17:22.652803 2026] [security2:error] [pid 53359:tid 53584] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyMvC2Xs1VMQlhsgaolgAAAm0"]
[Mon Jun 15 20:17:22.659509 2026] [security2:error] [pid 53359:tid 53592] [client 85.204.70.112:38918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/sites/default/files/"] [unique_id "ajCyMvC2Xs1VMQlhsgaokgAAAnU"]
[Mon Jun 15 20:17:22.683300 2026] [security2:error] [pid 51003:tid 51220] [client 34.173.239.49:33152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "hemani.finance"] [uri "/index.php"] [unique_id "ajCyMspsKyvb75pkSvaNiwAB5ks"]
[Mon Jun 15 20:17:22.809297 2026] [security2:error] [pid 51003:tid 51212] [client 85.204.70.112:40700] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/admin/controller/extension/extension/"] [unique_id "ajCyMspsKyvb75pkSvaNkwAAAd4"]
[Mon Jun 15 20:17:22.884672 2026] [security2:error] [pid 51003:tid 51190] [client 145.239.10.137:42838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.10.239.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kthemani.com"] [uri "/oggy.php"] [unique_id "ajCyMspsKyvb75pkSvaNlQAAAcg"], referer: http://kthemani.com/oggy.php
[Mon Jun 15 20:17:22.930247 2026] [security2:error] [pid 51003:tid 51177] [client 34.173.239.49:33152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "hemani.finance"] [uri "/index.php"] [unique_id "ajCyMspsKyvb75pkSvaNkAABu1M"]
[Mon Jun 15 20:17:22.970870 2026] [security2:error] [pid 53359:tid 53562] [client 51.68.236.72:26419] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "spinyy.com"] [uri "/robots.txt"] [unique_id "ajCyMvC2Xs1VMQlhsgaonwAAAlc"]
[Mon Jun 15 20:17:22.970948 2026] [security2:error] [pid 53359:tid 53562] [client 51.68.236.72:26419] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "spinyy.com"] [uri "/robots.txt"] [unique_id "ajCyMvC2Xs1VMQlhsgaonwAAAlc"]
[Mon Jun 15 20:17:22.985863 2026] [security2:error] [pid 53359:tid 53438] [remote 43.173.181.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.181.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mywordsnthoughts.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ajCyMvC2Xs1VMQlhsgaooAACJ0g"], referer: https://mywordsnthoughts.com/top-20-bollywood-duets-composed-by-anu-malik/
[Mon Jun 15 20:17:23.094593 2026] [security2:error] [pid 53359:tid 53585] [client 213.180.203.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyM_C2Xs1VMQlhsgaoqAAAAm4"]
[Mon Jun 15 20:17:23.097652 2026] [security2:error] [pid 53359:tid 53573] [client 213.180.203.5:54506] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyMvC2Xs1VMQlhsgaooQACYmo"]
[Mon Jun 15 20:17:23.141547 2026] [security2:error] [pid 53359:tid 53503] [client 85.204.70.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyM_C2Xs1VMQlhsgaoqQAAAhw"]
[Mon Jun 15 20:17:23.141567 2026] [security2:error] [pid 53359:tid 53503] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyM_C2Xs1VMQlhsgaoqQAAAhw"]
[Mon Jun 15 20:17:23.144903 2026] [security2:error] [pid 53359:tid 53608] [client 85.204.70.112:38918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/admin/controller/extension/extension/"] [unique_id "ajCyMvC2Xs1VMQlhsgaoowAAAoU"]
[Mon Jun 15 20:17:23.307613 2026] [security2:error] [pid 51003:tid 51150] [client 85.204.70.112:40700] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/"] [unique_id "ajCyM8psKyvb75pkSvaNqAAAAaA"]
[Mon Jun 15 20:17:23.376628 2026] [security2:error] [pid 51003:tid 51193] [client 72.45.116.197:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kthemani.com"] [uri "/index.php"] [unique_id "ajCyMcpsKyvb75pkSvaNbwAByyQ"]
[Mon Jun 15 20:17:23.477579 2026] [security2:error] [pid 53359:tid 53617] [client 34.173.239.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "hemani.finance"] [uri "/index.php"] [unique_id "ajCyM_C2Xs1VMQlhsgaowwAAAo4"]
[Mon Jun 15 20:17:23.547608 2026] [security2:error] [pid 53359:tid 53596] [client 85.204.70.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyM_C2Xs1VMQlhsgapJgAAAnk"]
[Mon Jun 15 20:17:23.547639 2026] [security2:error] [pid 53359:tid 53596] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyM_C2Xs1VMQlhsgapJgAAAnk"]
[Mon Jun 15 20:17:23.555520 2026] [security2:error] [pid 53359:tid 53591] [client 85.204.70.112:38918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/"] [unique_id "ajCyM_C2Xs1VMQlhsgapJAAAAnQ"]
[Mon Jun 15 20:17:23.696087 2026] [security2:error] [pid 51003:tid 51185] [client 85.204.70.112:40700] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/components/"] [unique_id "ajCyM8psKyvb75pkSvaNxwAAAcM"]
[Mon Jun 15 20:17:23.843139 2026] [security2:error] [pid 53359:tid 53610] [client 5.255.231.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyM_C2Xs1VMQlhsgapMwAAAoc"]
[Mon Jun 15 20:17:23.846492 2026] [security2:error] [pid 51003:tid 51192] [client 5.255.231.51:37800] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyM8psKyvb75pkSvaNyAABygE"]
[Mon Jun 15 20:17:23.928518 2026] [security2:error] [pid 53359:tid 53613] [client 85.204.70.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyM_C2Xs1VMQlhsgapNwAAAoo"]
[Mon Jun 15 20:17:23.928543 2026] [security2:error] [pid 53359:tid 53613] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyM_C2Xs1VMQlhsgapNwAAAoo"]
[Mon Jun 15 20:17:23.935313 2026] [security2:error] [pid 53359:tid 53521] [client 85.204.70.112:38918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/components/"] [unique_id "ajCyM_C2Xs1VMQlhsgapNAAAAi4"]
[Mon Jun 15 20:17:24.096301 2026] [security2:error] [pid 51003:tid 51236] [client 85.204.70.112:40700] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/admin/uploads/images/"] [unique_id "ajCyNMpsKyvb75pkSvaN0gAAAfY"]
[Mon Jun 15 20:17:24.149536 2026] [security2:error] [pid 53359:tid 53594] [client 57.141.14.102:46437] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "majividyarthikes.com"] [uri "/index.php"] [unique_id "ajCyM_C2Xs1VMQlhsgapOAACdzE"]
[Mon Jun 15 20:17:24.310527 2026] [security2:error] [pid 53359:tid 53614] [client 57.141.14.9:52492] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyNPC2Xs1VMQlhsgapQwACi34"]
[Mon Jun 15 20:17:24.378314 2026] [security2:error] [pid 51003:tid 51252] [client 85.204.70.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyNMpsKyvb75pkSvaN1gAAAgY"]
[Mon Jun 15 20:17:24.378351 2026] [security2:error] [pid 51003:tid 51252] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyNMpsKyvb75pkSvaN1gAAAgY"]
[Mon Jun 15 20:17:24.418791 2026] [security2:error] [pid 53359:tid 53616] [client 85.204.70.112:38918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/admin/uploads/images/"] [unique_id "ajCyNPC2Xs1VMQlhsgapRAAAAo0"]
[Mon Jun 15 20:17:24.426810 2026] [security2:error] [pid 51003:tid 51098] [remote 103.228.226.45:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.smgl.org"] [uri "/product-category/wholesale-sterling-silver-rings/prong-setting-rings-rings/"] [unique_id "ajCyNMpsKyvb75pkSvaN3QABnF4"]
[Mon Jun 15 20:17:24.463447 2026] [security2:error] [pid 51003:tid 51166] [client 95.108.213.212:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyNMpsKyvb75pkSvaN3AAAAbA"]
[Mon Jun 15 20:17:24.468905 2026] [security2:error] [pid 53359:tid 53560] [client 95.108.213.212:47254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyNPC2Xs1VMQlhsgapRQACVQM"]
[Mon Jun 15 20:17:24.592366 2026] [security2:error] [pid 51003:tid 51201] [client 85.204.70.112:40700] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/wp-content/plugins/classic-editor/"] [unique_id "ajCyNMpsKyvb75pkSvaN6AAAAdM"]
[Mon Jun 15 20:17:24.851012 2026] [security2:error] [pid 51003:tid 51242] [client 85.204.70.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyNMpsKyvb75pkSvaN6gAAAfw"]
[Mon Jun 15 20:17:24.851037 2026] [security2:error] [pid 51003:tid 51242] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyNMpsKyvb75pkSvaN6gAAAfw"]
[Mon Jun 15 20:17:24.927059 2026] [security2:error] [pid 53359:tid 53595] [client 85.204.70.112:38918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/wp-content/plugins/classic-editor/"] [unique_id "ajCyNPC2Xs1VMQlhsgapUgAAAng"]
[Mon Jun 15 20:17:25.094106 2026] [security2:error] [pid 51003:tid 51210] [client 85.204.70.112:40700] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/wp-content/fonts/"] [unique_id "ajCyNcpsKyvb75pkSvaN7wAAAdw"]
[Mon Jun 15 20:17:25.284168 2026] [security2:error] [pid 53359:tid 53387] [remote 57.141.14.38:34793] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyNfC2Xs1VMQlhsgapYgACWBU"]
[Mon Jun 15 20:17:25.316936 2026] [security2:error] [pid 53359:tid 53499] [client 85.204.70.112:38918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "geekjuggernaut.com"] [uri "/wp-content/fonts/"] [unique_id "ajCyNfC2Xs1VMQlhsgapaAAAAhg"]
[Mon Jun 15 20:17:25.395910 2026] [security2:error] [pid 53359:tid 53491] [remote 74.7.242.56:35902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.242.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.softhubtechno.ehx.czu.mybluehostin.me"] [uri "/images/js/Admin/logo/images/clients/images/testimonials/img/img/contact.php"] [unique_id "ajCyNfC2Xs1VMQlhsgapbgACZn0"], referer: https://www.softhubtechno.ehx.czu.mybluehostin.me/images/js/Admin/logo/images/clients/images/testimonials/img/img/logo.png
[Mon Jun 15 20:17:25.421401 2026] [security2:error] [pid 53359:tid 53436] [remote 64.131.86.2:50234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.86.131.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vertiport-holdings.us"] [uri "/wp-login.php"] [unique_id "ajCyNfC2Xs1VMQlhsgapbwACY0Y"]
[Mon Jun 15 20:17:25.447748 2026] [security2:error] [pid 51003:tid 51160] [client 85.204.70.112:40700] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/wp-content/plugins/contact-form-7/admin/js/"] [unique_id "ajCyNcpsKyvb75pkSvaN9QAAAao"]
[Mon Jun 15 20:17:25.501515 2026] [security2:error] [pid 53359:tid 53619] [client 5.255.231.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyNfC2Xs1VMQlhsgapcQAAApA"]
[Mon Jun 15 20:17:25.504778 2026] [security2:error] [pid 53359:tid 53540] [client 5.255.231.201:51434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyNfC2Xs1VMQlhsgapbQACQXk"]
[Mon Jun 15 20:17:25.585118 2026] [security2:error] [pid 53359:tid 53391] [remote 64.131.86.2:50234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.86.131.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vertiport-holdings.us"] [uri "/wp-login.php"] [unique_id "ajCyNfC2Xs1VMQlhsgapdQACYhk"], referer: https://vertiport-holdings.us/wp-login.php
[Mon Jun 15 20:17:25.703277 2026] [security2:error] [pid 53359:tid 53615] [client 213.180.203.168:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyNfC2Xs1VMQlhsgapeAAAAow"]
[Mon Jun 15 20:17:25.706620 2026] [security2:error] [pid 53359:tid 53546] [client 213.180.203.168:51190] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyNfC2Xs1VMQlhsgapdAACRzw"]
[Mon Jun 15 20:17:25.999911 2026] [security2:error] [pid 51003:tid 51236] [client 85.204.70.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyNcpsKyvb75pkSvaN_wAAAfY"]
[Mon Jun 15 20:17:25.999937 2026] [security2:error] [pid 51003:tid 51236] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyNcpsKyvb75pkSvaN_wAAAfY"]
[Mon Jun 15 20:17:26.001541 2026] [security2:error] [pid 51003:tid 51235] [client 5.255.231.198:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyNcpsKyvb75pkSvaOAwAAAfU"]
[Mon Jun 15 20:17:26.003234 2026] [security2:error] [pid 53359:tid 53567] [client 5.255.231.198:48856] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyNfC2Xs1VMQlhsgapfAACXGA"]
[Mon Jun 15 20:17:26.014088 2026] [security2:error] [pid 53359:tid 53600] [client 103.125.146.42:36791] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/options.php"] [unique_id "ajCyNvC2Xs1VMQlhsgapgwAAAn0"]
[Mon Jun 15 20:17:26.058001 2026] [security2:error] [pid 53359:tid 53604] [client 213.180.203.126:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyNvC2Xs1VMQlhsgapggAAAoE"]
[Mon Jun 15 20:17:26.060305 2026] [security2:error] [pid 51003:tid 51217] [client 213.180.203.126:47566] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyNcpsKyvb75pkSvaOAgAB43o"]
[Mon Jun 15 20:17:26.125564 2026] [security2:error] [pid 51003:tid 51212] [client 85.204.70.112:37828] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/wp-content/plugins/contact-form-7/admin/js/"] [unique_id "ajCyNcpsKyvb75pkSvaN_gAAAd4"]
[Mon Jun 15 20:17:26.226248 2026] [security2:error] [pid 51003:tid 51245] [client 192.140.64.94:29678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.64.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCyNspsKyvb75pkSvaOEQAAAf8"]
[Mon Jun 15 20:17:26.231173 2026] [security2:error] [pid 51003:tid 51245] [client 192.140.64.94:29678] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCyNspsKyvb75pkSvaOEQAAAf8"]
[Mon Jun 15 20:17:26.247895 2026] [security2:error] [pid 53359:tid 53612] [client 57.141.14.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hemani.finance"] [uri "/index.php"] [unique_id "ajCyNfC2Xs1VMQlhsgapfwAAAok"]
[Mon Jun 15 20:17:26.374602 2026] [security2:error] [pid 51003:tid 51145] [client 43.173.180.114:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCyNspsKyvb75pkSvaOBwABm1A"]
[Mon Jun 15 20:17:26.394513 2026] [security2:error] [pid 51003:tid 51158] [client 85.204.70.112:40700] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/wp-content/plugins/contact-form-7/"] [unique_id "ajCyNspsKyvb75pkSvaOFQAAAag"]
[Mon Jun 15 20:17:26.406343 2026] [security2:error] [pid 53359:tid 53577] [client 103.125.146.72:21323] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-admin/maint/includes/"] [unique_id "ajCyNvC2Xs1VMQlhsgaplQAAAmY"]
[Mon Jun 15 20:17:26.554536 2026] [security2:error] [pid 51003:tid 51175] [client 5.255.231.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyNspsKyvb75pkSvaOFwAAAbk"]
[Mon Jun 15 20:17:26.557276 2026] [security2:error] [pid 51003:tid 51150] [client 5.255.231.203:49916] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyNspsKyvb75pkSvaOFgABoD4"]
[Mon Jun 15 20:17:26.636687 2026] [security2:error] [pid 53359:tid 53587] [client 85.204.70.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyNvC2Xs1VMQlhsgapmgAAAnA"]
[Mon Jun 15 20:17:26.636712 2026] [security2:error] [pid 53359:tid 53587] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyNvC2Xs1VMQlhsgapmgAAAnA"]
[Mon Jun 15 20:17:26.764810 2026] [security2:error] [pid 51003:tid 51242] [client 85.204.70.112:37828] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/wp-content/plugins/contact-form-7/"] [unique_id "ajCyNspsKyvb75pkSvaOGQAAAeI"]
[Mon Jun 15 20:17:26.794356 2026] [security2:error] [pid 53359:tid 53423] [remote 104.243.207.8:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.smgl.org"] [uri "/product-category/wholesale-sterling-silver-rings/prong-setting-rings-rings/"] [unique_id "ajCyNvC2Xs1VMQlhsgapnwACVzk"], referer: https://www.smgl.org/
[Mon Jun 15 20:17:26.801606 2026] [security2:error] [pid 51003:tid 51142] [client 103.125.146.75:29169] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/images/"] [unique_id "ajCyNspsKyvb75pkSvaOIwAAAZg"]
[Mon Jun 15 20:17:26.912366 2026] [security2:error] [pid 51003:tid 51213] [client 85.204.70.112:40700] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/wordpress/"] [unique_id "ajCyNspsKyvb75pkSvaOJgAAAd8"]
[Mon Jun 15 20:17:27.019243 2026] [security2:error] [pid 53359:tid 53570] [client 87.250.224.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyNvC2Xs1VMQlhsgappgAAAl8"]
[Mon Jun 15 20:17:27.023357 2026] [security2:error] [pid 51003:tid 51169] [client 87.250.224.5:43360] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyNspsKyvb75pkSvaOJwABs0Y"]
[Mon Jun 15 20:17:27.061969 2026] [security2:error] [pid 53359:tid 53620] [client 95.108.213.131:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyN_C2Xs1VMQlhsgapqwAAApE"]
[Mon Jun 15 20:17:27.065105 2026] [security2:error] [pid 51003:tid 51154] [client 95.108.213.131:47918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyNspsKyvb75pkSvaOKAABpFI"]
[Mon Jun 15 20:17:27.194769 2026] [security2:error] [pid 53359:tid 53618] [client 103.125.146.54:61097] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-admin/css/admin.php"] [unique_id "ajCyN_C2Xs1VMQlhsgapsAAAAo8"]
[Mon Jun 15 20:17:27.251232 2026] [security2:error] [pid 53359:tid 53595] [client 57.141.14.73:27768] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyN_C2Xs1VMQlhsgaprwACeA0"]
[Mon Jun 15 20:17:27.280713 2026] [security2:error] [pid 53359:tid 53504] [client 85.204.70.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyN_C2Xs1VMQlhsgapsQAAAh0"]
[Mon Jun 15 20:17:27.280740 2026] [security2:error] [pid 53359:tid 53504] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyN_C2Xs1VMQlhsgapsQAAAh0"]
[Mon Jun 15 20:17:27.395962 2026] [security2:error] [pid 51003:tid 51170] [client 85.204.70.112:37828] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/wordpress/"] [unique_id "ajCyN8psKyvb75pkSvaOLgAAAbQ"]
[Mon Jun 15 20:17:27.527645 2026] [security2:error] [pid 51003:tid 51153] [client 85.204.70.112:40700] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/wp-admin/images/"] [unique_id "ajCyN8psKyvb75pkSvaOOgAAAaM"]
[Mon Jun 15 20:17:27.565561 2026] [security2:error] [pid 53359:tid 53525] [client 213.180.203.127:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyN_C2Xs1VMQlhsgapvAAAAjI"]
[Mon Jun 15 20:17:27.567384 2026] [security2:error] [pid 51003:tid 51219] [client 213.180.203.127:57128] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyN8psKyvb75pkSvaONwAB5Ss"]
[Mon Jun 15 20:17:27.588382 2026] [security2:error] [pid 53359:tid 53498] [client 103.125.146.58:26657] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/666.php"] [unique_id "ajCyN_C2Xs1VMQlhsgapwQAAAhc"]
[Mon Jun 15 20:17:27.641508 2026] [security2:error] [pid 53359:tid 53541] [client 5.255.231.109:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyN_C2Xs1VMQlhsgapwgAAAkI"]
[Mon Jun 15 20:17:27.644183 2026] [security2:error] [pid 53359:tid 53604] [client 57.141.14.89:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aarohiarts.org"] [uri "/index.php"] [unique_id "ajCyN_C2Xs1VMQlhsgapuAAAAoE"]
[Mon Jun 15 20:17:27.644833 2026] [security2:error] [pid 53359:tid 53610] [client 5.255.231.109:61830] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyN_C2Xs1VMQlhsgapuwAChyU"]
[Mon Jun 15 20:17:27.763931 2026] [autoindex:error] [pid 51003:tid 51194] [client 85.204.70.112:37828] AH01276: Cannot serve directory /home4/dreamsta/public_html/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:17:27.764695 2026] [security2:error] [pid 51003:tid 51194] [client 85.204.70.112:37828] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "geekjuggernaut.com"] [uri "/wp-admin/images/"] [unique_id "ajCyN8psKyvb75pkSvaOPQAAAcw"]
[Mon Jun 15 20:17:27.805681 2026] [security2:error] [pid 51003:tid 51231] [client 45.170.58.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kthemani.com"] [uri "/index.php"] [unique_id "ajCyNcpsKyvb75pkSvaN_QAAAfE"]
[Mon Jun 15 20:17:27.920715 2026] [security2:error] [pid 51003:tid 51191] [client 85.204.70.112:40700] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/wp-content/plugins/wordpress-seo/js/dist/"] [unique_id "ajCyN8psKyvb75pkSvaOQQAAAck"]
[Mon Jun 15 20:17:27.994605 2026] [security2:error] [pid 51003:tid 51182] [client 103.125.146.78:22905] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/chosen.php"] [unique_id "ajCyN8psKyvb75pkSvaORgAAAcA"]
[Mon Jun 15 20:17:28.045154 2026] [security2:error] [pid 51003:tid 51146] [client 5.255.231.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyOMpsKyvb75pkSvaORwAAAZw"]
[Mon Jun 15 20:17:28.051925 2026] [security2:error] [pid 51003:tid 51203] [client 5.255.231.37:57040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyN8psKyvb75pkSvaOQgAB1RQ"]
[Mon Jun 15 20:17:28.141139 2026] [autoindex:error] [pid 53359:tid 53518] [client 85.204.70.112:0] AH01276: Cannot serve directory /home4/dreamsta/public_html/wp-content/plugins/wordpress-seo/js/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:17:28.141634 2026] [security2:error] [pid 53359:tid 53518] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCyOPC2Xs1VMQlhsgap1AAAAis"]
[Mon Jun 15 20:17:28.167572 2026] [security2:error] [pid 51003:tid 51166] [client 85.204.70.112:37828] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "geekjuggernaut.com"] [uri "/wp-content/plugins/wordpress-seo/js/dist/"] [unique_id "ajCyOMpsKyvb75pkSvaOSQAAAbA"]
[Mon Jun 15 20:17:28.281913 2026] [security2:error] [pid 53359:tid 53539] [client 47.79.201.221:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "societytodaynews.com"] [uri "/index.php"] [unique_id "ajCyOPC2Xs1VMQlhsgap0AAAAkA"], referer: https://www.google.com/
[Mon Jun 15 20:17:28.300159 2026] [security2:error] [pid 51003:tid 51150] [client 85.204.70.112:40700] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/wp-content/plugins/wordpress-seo/"] [unique_id "ajCyOMpsKyvb75pkSvaOTwAAAaA"]
[Mon Jun 15 20:17:28.418536 2026] [security2:error] [pid 53359:tid 53576] [client 103.125.146.50:24189] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-admin/network/"] [unique_id "ajCyOPC2Xs1VMQlhsgap3QAAAmU"]
[Mon Jun 15 20:17:28.480622 2026] [security2:error] [pid 51003:tid 51189] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "geekjuggernaut.com"] [uri "/wp-content/plugins/wordpress-seo/index.php"] [unique_id "ajCyOMpsKyvb75pkSvaOUgAAAcc"]
[Mon Jun 15 20:17:28.482613 2026] [security2:error] [pid 51003:tid 51138] [client 85.204.70.112:37828] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "geekjuggernaut.com"] [uri "/wp-content/plugins/wordpress-seo/"] [unique_id "ajCyOMpsKyvb75pkSvaOUQAAAZQ"]
[Mon Jun 15 20:17:28.504467 2026] [security2:error] [pid 53359:tid 53542] [client 57.141.14.101:60986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyOPC2Xs1VMQlhsgap2wACQ3Y"]
[Mon Jun 15 20:17:28.513311 2026] [security2:error] [pid 51003:tid 51250] [client 213.180.203.177:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyOMpsKyvb75pkSvaOUwAAAgQ"]
[Mon Jun 15 20:17:28.516198 2026] [security2:error] [pid 53359:tid 53532] [client 213.180.203.177:39960] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyOPC2Xs1VMQlhsgap3gACOQI"]
[Mon Jun 15 20:17:28.611768 2026] [security2:error] [pid 51003:tid 51232] [client 85.204.70.112:40700] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/js/"] [unique_id "ajCyOMpsKyvb75pkSvaOVAAAAfI"]
[Mon Jun 15 20:17:28.755030 2026] [security2:error] [pid 53359:tid 53525] [client 65.111.14.238:15369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.14.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rajunandkardeputycollector.blog"] [uri "/wp-login.php"] [unique_id "ajCyOPC2Xs1VMQlhsgap6gAAAjI"], referer: https://rajunandkardeputycollector.blog/wp-login.php
[Mon Jun 15 20:17:28.814478 2026] [security2:error] [pid 53359:tid 53606] [client 103.125.146.48:63071] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/plugins/filester/assets/css/404.php"] [unique_id "ajCyOPC2Xs1VMQlhsgap7QAAAoM"]
[Mon Jun 15 20:17:28.909097 2026] [security2:error] [pid 53359:tid 53523] [client 85.204.70.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyOPC2Xs1VMQlhsgap7wAAAjA"]
[Mon Jun 15 20:17:28.909119 2026] [security2:error] [pid 53359:tid 53523] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyOPC2Xs1VMQlhsgap7wAAAjA"]
[Mon Jun 15 20:17:28.914117 2026] [security2:error] [pid 51003:tid 51181] [client 85.204.70.112:37828] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/js/"] [unique_id "ajCyOMpsKyvb75pkSvaOWAAAAb8"]
[Mon Jun 15 20:17:29.114908 2026] [security2:error] [pid 51003:tid 51243] [client 85.204.70.112:40700] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/wp-content/plugins/woocommerce/assets/js/"] [unique_id "ajCyOcpsKyvb75pkSvaOXwAAAf0"]
[Mon Jun 15 20:17:29.120364 2026] [security2:error] [pid 53359:tid 53509] [client 5.255.231.127:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyOfC2Xs1VMQlhsgap9wAAAiI"]
[Mon Jun 15 20:17:29.123715 2026] [security2:error] [pid 53359:tid 53512] [client 5.255.231.127:52536] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyOPC2Xs1VMQlhsgap8wACJVc"]
[Mon Jun 15 20:17:29.203285 2026] [security2:error] [pid 51003:tid 51187] [client 103.125.146.55:46653] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/edit-tags.php"] [unique_id "ajCyOcpsKyvb75pkSvaOYgAAAcU"]
[Mon Jun 15 20:17:29.313713 2026] [security2:error] [pid 53359:tid 53534] [client 183.83.134.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCyOfC2Xs1VMQlhsgap-QACO0M"], referer: https://mywordsnthoughts.com/mounam-polum-madhuram-song-from-sagara-sangamam-lyrics-in-english-with-translation/
[Mon Jun 15 20:17:29.339935 2026] [security2:error] [pid 53359:tid 53585] [client 217.181.91.200:26691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.91.181.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rajunandkardeputycollector.blog"] [uri "/wp-login.php"] [unique_id "ajCyOfC2Xs1VMQlhsgaqAQAAAm4"], referer: https://rajunandkardeputycollector.blog/wp-login.php
[Mon Jun 15 20:17:29.372234 2026] [security2:error] [pid 53359:tid 53545] [client 65.111.30.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.procrastinatingworker.imcorp.in"] [uri "/index.php"] [unique_id "ajCyOfC2Xs1VMQlhsgaqAAAAAkY"]
[Mon Jun 15 20:17:29.427799 2026] [security2:error] [pid 53359:tid 53518] [client 85.204.70.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyOfC2Xs1VMQlhsgaqAwAAAis"]
[Mon Jun 15 20:17:29.427822 2026] [security2:error] [pid 53359:tid 53518] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyOfC2Xs1VMQlhsgaqAwAAAis"]
[Mon Jun 15 20:17:29.442519 2026] [security2:error] [pid 51003:tid 51167] [client 85.204.70.112:37828] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/wp-content/plugins/woocommerce/assets/js/"] [unique_id "ajCyOcpsKyvb75pkSvaOaQAAAbE"]
[Mon Jun 15 20:17:29.596250 2026] [security2:error] [pid 51003:tid 51190] [client 85.204.70.112:40700] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/wp-content/plugins/woocommerce/"] [unique_id "ajCyOcpsKyvb75pkSvaObgAAAcg"]
[Mon Jun 15 20:17:29.604024 2026] [security2:error] [pid 53359:tid 53621] [client 103.125.146.31:52213] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/themes/chosen.php"] [unique_id "ajCyOfC2Xs1VMQlhsgaqCQAAApI"]
[Mon Jun 15 20:17:29.617050 2026] [security2:error] [pid 51003:tid 51196] [client 213.180.203.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyOcpsKyvb75pkSvaObQAAAc4"]
[Mon Jun 15 20:17:29.630804 2026] [security2:error] [pid 53359:tid 53580] [client 213.180.203.26:46828] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyOfC2Xs1VMQlhsgaqCAACaSQ"]
[Mon Jun 15 20:17:29.709904 2026] [security2:error] [pid 51003:tid 51018] [remote 54.39.210.220:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.moviezshow.com"] [uri "/chamunda-1999-watch-online-full-movieraj-premi-satnam-kaur-jyoti-rana-haider-afreen-anil-nagrath/feed/"] [unique_id "ajCyOcpsKyvb75pkSvaOcgAB6g4"]
[Mon Jun 15 20:17:29.710050 2026] [security2:error] [pid 51003:tid 51224] [client 54.39.210.220:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.moviezshow.com"] [uri "/chamunda-1999-watch-online-full-movieraj-premi-satnam-kaur-jyoti-rana-haider-afreen-anil-nagrath/feed/"] [unique_id "ajCyOcpsKyvb75pkSvaOcgAB6g4"]
[Mon Jun 15 20:17:29.828248 2026] [security2:error] [pid 53359:tid 53567] [client 85.204.70.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyOfC2Xs1VMQlhsgaqDQAAAlw"]
[Mon Jun 15 20:17:29.828269 2026] [security2:error] [pid 53359:tid 53567] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyOfC2Xs1VMQlhsgaqDQAAAlw"]
[Mon Jun 15 20:17:29.834776 2026] [security2:error] [pid 51003:tid 51177] [client 85.204.70.112:37828] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/wp-content/plugins/woocommerce/"] [unique_id "ajCyOcpsKyvb75pkSvaOcwAAAbs"]
[Mon Jun 15 20:17:29.893388 2026] [security2:error] [pid 53359:tid 53517] [client 65.111.1.107:14385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.1.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rajunandkardeputycollector.blog"] [uri "/wp-login.php"] [unique_id "ajCyOfC2Xs1VMQlhsgaqFAAAAio"], referer: https://rajunandkardeputycollector.blog/wp-login.php
[Mon Jun 15 20:17:29.985103 2026] [security2:error] [pid 53359:tid 53417] [remote 2a03:2880:f806:36:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ruchini.hemani.finance"] [uri "/index.php"] [unique_id "ajCyOfC2Xs1VMQlhsgaqFgACNjM"]
[Mon Jun 15 20:17:29.991805 2026] [security2:error] [pid 51003:tid 51146] [client 85.204.70.112:40700] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/wp-admin/meta/"] [unique_id "ajCyOcpsKyvb75pkSvaOegAAAZw"]
[Mon Jun 15 20:17:29.995299 2026] [security2:error] [pid 53359:tid 53598] [client 103.125.146.30:20933] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/IXR/"] [unique_id "ajCyOfC2Xs1VMQlhsgaqHAAAAns"]
[Mon Jun 15 20:17:30.075993 2026] [security2:error] [pid 53359:tid 53464] [remote 57.141.14.66:47912] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyOfC2Xs1VMQlhsgaqGgACh2I"]
[Mon Jun 15 20:17:30.104340 2026] [security2:error] [pid 53359:tid 53561] [client 87.250.224.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyOvC2Xs1VMQlhsgaqIQAAAlY"]
[Mon Jun 15 20:17:30.108983 2026] [security2:error] [pid 53359:tid 53502] [client 87.250.224.23:37144] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyOvC2Xs1VMQlhsgaqHQACG1w"]
[Mon Jun 15 20:17:30.218365 2026] [security2:error] [pid 51003:tid 51203] [client 85.204.70.112:37828] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyOspsKyvb75pkSvaOewAAAdU"]
[Mon Jun 15 20:17:30.218387 2026] [security2:error] [pid 51003:tid 51203] [client 85.204.70.112:37828] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/index.php"] [unique_id "ajCyOspsKyvb75pkSvaOewAAAdU"]
[Mon Jun 15 20:17:30.395546 2026] [security2:error] [pid 51003:tid 51223] [client 85.204.70.112:40700] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/wp-admin/network/"] [unique_id "ajCyOspsKyvb75pkSvaOhAAAAek"]
[Mon Jun 15 20:17:30.416402 2026] [security2:error] [pid 51003:tid 51175] [client 103.125.146.31:34991] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/uploads/2024/"] [unique_id "ajCyOspsKyvb75pkSvaOhgAAAbk"]
[Mon Jun 15 20:17:30.501141 2026] [security2:error] [pid 53359:tid 53572] [client 213.180.203.110:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyOvC2Xs1VMQlhsgaqJwAAAmE"]
[Mon Jun 15 20:17:30.504927 2026] [security2:error] [pid 51003:tid 51259] [client 213.180.203.110:55438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyOspsKyvb75pkSvaOhQACDRw"]
[Mon Jun 15 20:17:30.626339 2026] [security2:error] [pid 51003:tid 51140] [client 85.204.70.112:37828] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "geekjuggernaut.com"] [uri "/wp-admin/network/index.php"] [unique_id "ajCyOspsKyvb75pkSvaOiAAAAZY"]
[Mon Jun 15 20:17:30.819011 2026] [security2:error] [pid 51003:tid 51238] [client 85.204.70.112:37828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "geekjuggernaut.com"] [uri "/wp-login.php"] [unique_id "ajCyOspsKyvb75pkSvaOjwAAAfg"]
[Mon Jun 15 20:17:30.819164 2026] [security2:error] [pid 51003:tid 51238] [client 85.204.70.112:37828] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "geekjuggernaut.com"] [uri "/wp-login.php"] [unique_id "ajCyOspsKyvb75pkSvaOjwAAAfg"]
[Mon Jun 15 20:17:30.960946 2026] [security2:error] [pid 51003:tid 51189] [client 47.79.202.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "designhub1610.com"] [uri "/index.php"] [unique_id "ajCyOspsKyvb75pkSvaOjAABxwg"], referer: https://www.google.com/
[Mon Jun 15 20:17:30.994624 2026] [security2:error] [pid 53359:tid 53583] [client 213.180.203.168:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyOvC2Xs1VMQlhsgaqOAAAAmw"]
[Mon Jun 15 20:17:30.997235 2026] [security2:error] [pid 53359:tid 53531] [client 213.180.203.168:63420] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyOvC2Xs1VMQlhsgaqMwACOAQ"]
[Mon Jun 15 20:17:31.004123 2026] [security2:error] [pid 51003:tid 51201] [client 85.204.70.112:40700] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/wp-admin/user/"] [unique_id "ajCyO8psKyvb75pkSvaOkQAAAdM"]
[Mon Jun 15 20:17:31.487784 2026] [security2:error] [pid 53359:tid 53525] [client 85.204.70.112:41610] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "geekjuggernaut.com"] [uri "/wp-admin/user/index.php"] [unique_id "ajCyO_C2Xs1VMQlhsgaqQgAAAjI"]
[Mon Jun 15 20:17:31.531253 2026] [security2:error] [pid 51003:tid 51148] [client 5.255.231.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyO8psKyvb75pkSvaOnQAAAZ4"]
[Mon Jun 15 20:17:31.533885 2026] [security2:error] [pid 53359:tid 53559] [client 5.255.231.201:36082] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyO_C2Xs1VMQlhsgaqRQACVG8"]
[Mon Jun 15 20:17:31.615891 2026] [security2:error] [pid 53359:tid 53599] [client 85.204.70.112:41610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "geekjuggernaut.com"] [uri "/wp-login.php"] [unique_id "ajCyO_C2Xs1VMQlhsgaqRwAAAnw"]
[Mon Jun 15 20:17:31.615980 2026] [security2:error] [pid 53359:tid 53599] [client 85.204.70.112:41610] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "geekjuggernaut.com"] [uri "/wp-login.php"] [unique_id "ajCyO_C2Xs1VMQlhsgaqRwAAAnw"]
[Mon Jun 15 20:17:31.646175 2026] [security2:error] [pid 51003:tid 51168] [client 57.141.14.67:56437] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyO8psKyvb75pkSvaOngABslw"]
[Mon Jun 15 20:17:31.746066 2026] [security2:error] [pid 51003:tid 51236] [client 85.204.70.112:40700] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/wp-content/"] [unique_id "ajCyO8psKyvb75pkSvaOpAAAAfY"]
[Mon Jun 15 20:17:32.016572 2026] [security2:error] [pid 53359:tid 53514] [client 5.255.231.198:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyO_C2Xs1VMQlhsgaqUQAAAic"]
[Mon Jun 15 20:17:32.038942 2026] [security2:error] [pid 53359:tid 53614] [client 5.255.231.198:48868] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyO_C2Xs1VMQlhsgaqTwACi1Y"]
[Mon Jun 15 20:17:32.074630 2026] [security2:error] [pid 51003:tid 51245] [client 2804:75d4:bfc9:cf00:7559:5826:1ba6:d065:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kthemani.com"] [uri "/index.php"] [unique_id "ajCyOspsKyvb75pkSvaOfgAB_zQ"]
[Mon Jun 15 20:17:32.231793 2026] [security2:error] [pid 51003:tid 51207] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "geekjuggernaut.com"] [uri "/wp-content/index.php"] [unique_id "ajCyPMpsKyvb75pkSvaOrgAAAdk"]
[Mon Jun 15 20:17:32.234456 2026] [security2:error] [pid 53359:tid 53503] [client 85.204.70.112:41618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "geekjuggernaut.com"] [uri "/wp-content/"] [unique_id "ajCyPPC2Xs1VMQlhsgaqVwAAAhw"]
[Mon Jun 15 20:17:32.312955 2026] [security2:error] [pid 53359:tid 53608] [client 31.219.209.201:64879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.209.219.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCyPPC2Xs1VMQlhsgaqWgAAAoU"]
[Mon Jun 15 20:17:32.313047 2026] [security2:error] [pid 53359:tid 53608] [client 31.219.209.201:64879] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCyPPC2Xs1VMQlhsgaqWgAAAoU"]
[Mon Jun 15 20:17:32.412476 2026] [security2:error] [pid 51003:tid 51149] [client 85.204.70.112:40700] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/wp-content/plugins/"] [unique_id "ajCyPMpsKyvb75pkSvaOtAAAAZ8"]
[Mon Jun 15 20:17:32.551594 2026] [security2:error] [pid 53359:tid 53519] [client 213.180.203.126:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyPPC2Xs1VMQlhsgaqXgAAAiw"]
[Mon Jun 15 20:17:32.556065 2026] [security2:error] [pid 53359:tid 53579] [client 213.180.203.126:61522] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyPPC2Xs1VMQlhsgaqXAACaEU"]
[Mon Jun 15 20:17:32.693928 2026] [security2:error] [pid 53359:tid 53515] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "geekjuggernaut.com"] [uri "/wp-content/plugins/index.php"] [unique_id "ajCyPPC2Xs1VMQlhsgaqYQAAAig"]
[Mon Jun 15 20:17:32.697455 2026] [security2:error] [pid 53359:tid 53622] [client 85.204.70.112:41618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "geekjuggernaut.com"] [uri "/wp-content/plugins/"] [unique_id "ajCyPPC2Xs1VMQlhsgaqXwAAApM"]
[Mon Jun 15 20:17:32.826371 2026] [security2:error] [pid 51003:tid 51147] [client 85.204.70.112:40700] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/wp-content/themes/"] [unique_id "ajCyPMpsKyvb75pkSvaOugAAAZ0"]
[Mon Jun 15 20:17:32.989060 2026] [security2:error] [pid 51003:tid 51175] [client 47.79.200.110:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "societytodaynews.com"] [uri "/index.php"] [unique_id "ajCyPMpsKyvb75pkSvaOtwAAAbk"], referer: https://www.google.com/
[Mon Jun 15 20:17:33.033646 2026] [security2:error] [pid 53359:tid 53599] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "geekjuggernaut.com"] [uri "/wp-content/themes/index.php"] [unique_id "ajCyPfC2Xs1VMQlhsgaqbgAAAnw"]
[Mon Jun 15 20:17:33.036218 2026] [security2:error] [pid 53359:tid 53525] [client 85.204.70.112:41618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "geekjuggernaut.com"] [uri "/wp-content/themes/"] [unique_id "ajCyPfC2Xs1VMQlhsgaqaQAAAjI"]
[Mon Jun 15 20:17:33.094402 2026] [security2:error] [pid 51003:tid 51208] [client 5.255.231.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyPcpsKyvb75pkSvaOwgAAAdo"]
[Mon Jun 15 20:17:33.097151 2026] [security2:error] [pid 53359:tid 53578] [client 5.255.231.203:56746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyPfC2Xs1VMQlhsgaqbwACZ1k"]
[Mon Jun 15 20:17:33.196559 2026] [security2:error] [pid 51003:tid 51221] [client 85.204.70.112:40700] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/wp-admin/includes/"] [unique_id "ajCyPcpsKyvb75pkSvaOxwAAAec"]
[Mon Jun 15 20:17:33.242693 2026] [security2:error] [pid 51003:tid 51133] [client 57.141.14.73:63388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rohandasgupta.com"] [uri "/index.php"] [unique_id "ajCyPcpsKyvb75pkSvaOwQABj38"]
[Mon Jun 15 20:17:33.374690 2026] [autoindex:error] [pid 53359:tid 53540] [client 85.204.70.112:41618] AH01276: Cannot serve directory /home4/dreamsta/public_html/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:17:33.375181 2026] [security2:error] [pid 53359:tid 53540] [client 85.204.70.112:41618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "geekjuggernaut.com"] [uri "/wp-admin/includes/"] [unique_id "ajCyPfC2Xs1VMQlhsgaqegAAAkE"]
[Mon Jun 15 20:17:33.466120 2026] [security2:error] [pid 53359:tid 53571] [client 66.249.79.8:0] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "vernes.co.uk"] [uri "/robots.txt"] [unique_id "ajCyPfC2Xs1VMQlhsgaqfgAAAmA"]
[Mon Jun 15 20:17:33.513254 2026] [security2:error] [pid 51003:tid 51144] [client 57.141.14.66:47916] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyPcpsKyvb75pkSvaOzgABmlY"]
[Mon Jun 15 20:17:33.527593 2026] [security2:error] [pid 51003:tid 51187] [client 85.204.70.112:40700] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/wp-admin/"] [unique_id "ajCyPcpsKyvb75pkSvaO1AAAAcU"]
[Mon Jun 15 20:17:33.535807 2026] [security2:error] [pid 51003:tid 51257] [client 95.108.213.131:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyPcpsKyvb75pkSvaO0gAAAgs"]
[Mon Jun 15 20:17:33.539385 2026] [security2:error] [pid 53359:tid 53581] [client 95.108.213.131:47904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyPfC2Xs1VMQlhsgaqfwACalA"]
[Mon Jun 15 20:17:33.787653 2026] [security2:error] [pid 53359:tid 53591] [client 85.204.70.112:41618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "geekjuggernaut.com"] [uri "/wp-admin/index.php"] [unique_id "ajCyPfC2Xs1VMQlhsgaqhAAAAnQ"]
[Mon Jun 15 20:17:33.915898 2026] [security2:error] [pid 53359:tid 53618] [client 85.204.70.112:41618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "geekjuggernaut.com"] [uri "/wp-login.php"] [unique_id "ajCyPfC2Xs1VMQlhsgaqkAAAAo8"]
[Mon Jun 15 20:17:33.916014 2026] [security2:error] [pid 53359:tid 53618] [client 85.204.70.112:41618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "geekjuggernaut.com"] [uri "/wp-login.php"] [unique_id "ajCyPfC2Xs1VMQlhsgaqkAAAAo8"]
[Mon Jun 15 20:17:34.014988 2026] [security2:error] [pid 53359:tid 53517] [client 57.141.14.40:46334] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyPfC2Xs1VMQlhsgaqjgACKk4"]
[Mon Jun 15 20:17:34.034940 2026] [security2:error] [pid 53359:tid 53602] [client 57.141.14.64:42242] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fifthestate.agency"] [uri "/index.php"] [unique_id "ajCyPfC2Xs1VMQlhsgaqigACfzQ"]
[Mon Jun 15 20:17:34.050880 2026] [security2:error] [pid 53359:tid 53597] [client 87.250.224.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyPvC2Xs1VMQlhsgaqlgAAAno"]
[Mon Jun 15 20:17:34.053423 2026] [security2:error] [pid 53359:tid 53600] [client 87.250.224.5:57038] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyPfC2Xs1VMQlhsgaqkgACfQw"]
[Mon Jun 15 20:17:34.090247 2026] [security2:error] [pid 51003:tid 51193] [client 85.204.70.112:40700] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "geekjuggernaut.com"] [uri "/wp-content/upgrade/"] [unique_id "ajCyPspsKyvb75pkSvaO3AAAAcs"]
[Mon Jun 15 20:17:34.257304 2026] [security2:error] [pid 51003:tid 51127] [remote 115.78.9.138:47296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.9.78.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.brahmlagna.com"] [uri "/wp-login.php"] [unique_id "ajCyPspsKyvb75pkSvaO3QAB9Xs"]
[Mon Jun 15 20:17:34.492939 2026] [security2:error] [pid 53359:tid 53547] [client 5.255.231.109:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyPvC2Xs1VMQlhsgaqtAAAAkg"]
[Mon Jun 15 20:17:34.495827 2026] [security2:error] [pid 53359:tid 53606] [client 5.255.231.109:53178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyPvC2Xs1VMQlhsgaqrQACg3g"]
[Mon Jun 15 20:17:34.661001 2026] [autoindex:error] [pid 53359:tid 53567] [client 85.204.70.112:0] AH01276: Cannot serve directory /home4/dreamsta/public_html/wp-content/upgrade/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:17:34.661530 2026] [security2:error] [pid 53359:tid 53567] [client 85.204.70.112:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "geekjuggernaut.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCyPvC2Xs1VMQlhsgaquwAAAlw"]
[Mon Jun 15 20:17:34.664707 2026] [security2:error] [pid 53359:tid 53509] [client 85.204.70.112:41624] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "geekjuggernaut.com"] [uri "/wp-content/upgrade/"] [unique_id "ajCyPvC2Xs1VMQlhsgaquQAAAiI"]
[Mon Jun 15 20:17:34.761030 2026] [security2:error] [pid 53359:tid 53556] [client 57.141.14.8:32345] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rohandasgupta.com"] [uri "/index.php"] [unique_id "ajCyPvC2Xs1VMQlhsgaquAACUX4"]
[Mon Jun 15 20:17:34.983083 2026] [security2:error] [pid 53359:tid 53559] [client 213.180.203.127:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyPvC2Xs1VMQlhsgaqxwAAAlQ"]
[Mon Jun 15 20:17:34.986524 2026] [security2:error] [pid 51003:tid 51149] [client 213.180.203.127:62160] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyPspsKyvb75pkSvaO8QABn3I"]
[Mon Jun 15 20:17:35.006127 2026] [autoindex:error] [pid 51003:tid 51194] [client 134.122.111.44:52572] AH01276: Cannot serve directory /home1/rugqjjmy/public_html/cardinalhealthcorp/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:17:35.098351 2026] [security2:error] [pid 53359:tid 53532] [client 223.109.252.166:47688] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "spiritedblogger.com"] [uri "/navratri-celebration-in-different-indian-states/"] [unique_id "ajCyP_C2Xs1VMQlhsgaqzgAAAjk"]
[Mon Jun 15 20:17:35.098451 2026] [security2:error] [pid 53359:tid 53532] [client 223.109.252.166:47688] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "spiritedblogger.com"] [uri "/navratri-celebration-in-different-indian-states/"] [unique_id "ajCyP_C2Xs1VMQlhsgaqzgAAAjk"]
[Mon Jun 15 20:17:35.497649 2026] [security2:error] [pid 53359:tid 53573] [client 57.141.14.59:47333] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyP_C2Xs1VMQlhsgaq1gACYmY"]
[Mon Jun 15 20:17:35.522744 2026] [security2:error] [pid 53359:tid 53531] [client 5.255.231.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyP_C2Xs1VMQlhsgaq3AAAAjg"]
[Mon Jun 15 20:17:35.572320 2026] [security2:error] [pid 53359:tid 53601] [client 5.255.231.37:63112] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyP_C2Xs1VMQlhsgaq2AACflQ"]
[Mon Jun 15 20:17:35.808961 2026] [security2:error] [pid 53359:tid 53603] [client 103.125.146.76:41207] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/js/tinymce/skins/lightgray/"] [unique_id "ajCyP_C2Xs1VMQlhsgaq4wAAAoA"]
[Mon Jun 15 20:17:36.049856 2026] [security2:error] [pid 53359:tid 53500] [client 213.180.203.177:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyQPC2Xs1VMQlhsgaq6wAAAhk"]
[Mon Jun 15 20:17:36.052839 2026] [security2:error] [pid 53359:tid 53519] [client 213.180.203.177:39972] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyP_C2Xs1VMQlhsgaq5QACLEY"]
[Mon Jun 15 20:17:36.212895 2026] [security2:error] [pid 53359:tid 53520] [client 103.125.146.78:24449] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/themes.php"] [unique_id "ajCyQPC2Xs1VMQlhsgaq8AAAAi0"]
[Mon Jun 15 20:17:36.602593 2026] [security2:error] [pid 53359:tid 53620] [client 103.125.146.51:38073] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/admin/function.php"] [unique_id "ajCyQPC2Xs1VMQlhsgaq9gAAApE"]
[Mon Jun 15 20:17:36.788718 2026] [security2:error] [pid 51003:tid 51256] [client 192.140.64.94:29711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.64.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCyQMpsKyvb75pkSvaPDgAAAgo"]
[Mon Jun 15 20:17:36.789013 2026] [security2:error] [pid 51003:tid 51256] [client 192.140.64.94:29711] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCyQMpsKyvb75pkSvaPDgAAAgo"]
[Mon Jun 15 20:17:37.009716 2026] [security2:error] [pid 53359:tid 53596] [client 57.141.14.98:20900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyQPC2Xs1VMQlhsgaq-QACeTg"]
[Mon Jun 15 20:17:37.022591 2026] [security2:error] [pid 53359:tid 53566] [client 103.125.146.62:38243] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-admin/maint/chosen.php"] [unique_id "ajCyQfC2Xs1VMQlhsgaq_gAAAls"]
[Mon Jun 15 20:17:37.185612 2026] [security2:error] [pid 53359:tid 53460] [remote 74.208.140.41:44074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.140.208.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "legaleye.in"] [uri "/wp-login.php"] [unique_id "ajCyQfC2Xs1VMQlhsgarAwACNF4"]
[Mon Jun 15 20:17:37.194017 2026] [security2:error] [pid 53359:tid 53505] [client 45.84.107.172:441] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "gamergreatness.com"] [uri "/index.php"] [unique_id "ajCyQPC2Xs1VMQlhsgaq-gACHhQ"], referer: https://gamergreatness.com/community/topic/which-one-would-you-buy-xbox-series-x-or-xbox-series-s
[Mon Jun 15 20:17:37.310669 2026] [security2:error] [pid 51003:tid 51182] [client 74.119.118.204:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.diggysguide.com"] [uri "/index.php"] [unique_id "ajCyQcpsKyvb75pkSvaPHAAAAcA"]
[Mon Jun 15 20:17:37.313994 2026] [security2:error] [pid 53359:tid 53531] [client 74.119.118.204:36639] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.diggysguide.com"] [uri "/new-world/abandoned-port"] [unique_id "ajCyQfC2Xs1VMQlhsgarBQAAAjg"]
[Mon Jun 15 20:17:37.363522 2026] [security2:error] [pid 53359:tid 53423] [remote 74.208.140.41:44074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.140.208.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "legaleye.in"] [uri "/wp-login.php"] [unique_id "ajCyQfC2Xs1VMQlhsgarBgACXDk"], referer: https://legaleye.in/wp-login.php
[Mon Jun 15 20:17:37.414474 2026] [security2:error] [pid 51003:tid 51249] [client 103.125.146.77:55447] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/about.php"] [unique_id "ajCyQcpsKyvb75pkSvaPHQAAAgM"]
[Mon Jun 15 20:17:37.521581 2026] [security2:error] [pid 51003:tid 51169] [client 143.244.57.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.surveylaya.com"] [uri "/wp-content/themes/index.php"] [unique_id "ajCyQcpsKyvb75pkSvaPHwAAAbM"]
[Mon Jun 15 20:17:37.523327 2026] [security2:error] [pid 53359:tid 53542] [client 143.244.57.120:50966] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.surveylaya.com"] [uri "/wp-content/themes/"] [unique_id "ajCyQfC2Xs1VMQlhsgarBwAAAkM"]
[Mon Jun 15 20:17:37.811512 2026] [security2:error] [pid 53359:tid 53559] [client 103.125.146.53:53467] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-admin/css/colors/light/"] [unique_id "ajCyQfC2Xs1VMQlhsgarEQAAAlQ"]
[Mon Jun 15 20:17:37.927251 2026] [security2:error] [pid 53359:tid 53598] [client 77.181.117.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kthemani.com"] [uri "/index.php"] [unique_id "ajCyQPC2Xs1VMQlhsgaq7QAAAns"]
[Mon Jun 15 20:17:38.110218 2026] [security2:error] [pid 53359:tid 53403] [remote 89.58.31.106:49400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.31.58.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anatma.org"] [uri "/wp-login.php"] [unique_id "ajCyQvC2Xs1VMQlhsgarGQAChCU"]
[Mon Jun 15 20:17:38.240451 2026] [security2:error] [pid 53359:tid 53588] [client 103.125.146.77:49617] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/classwithtostring.php"] [unique_id "ajCyQvC2Xs1VMQlhsgarHAAAAnE"]
[Mon Jun 15 20:17:38.315370 2026] [security2:error] [pid 53359:tid 53390] [remote 89.58.31.106:49400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.31.58.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anatma.org"] [uri "/wp-login.php"] [unique_id "ajCyQvC2Xs1VMQlhsgarHwACjRg"], referer: https://anatma.org/wp-login.php
[Mon Jun 15 20:17:38.636464 2026] [security2:error] [pid 53359:tid 53507] [client 103.125.146.39:38549] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/blocks/comment-content/"] [unique_id "ajCyQvC2Xs1VMQlhsgarIwAAAiA"]
[Mon Jun 15 20:17:38.867425 2026] [security2:error] [pid 51003:tid 51219] [client 109.210.186.221:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kthemani.com"] [uri "/index.php"] [unique_id "ajCyQMpsKyvb75pkSvaPEAAB5XY"]
[Mon Jun 15 20:17:39.001305 2026] [security2:error] [pid 53359:tid 53511] [client 103.125.146.56:32079] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/blocks/comment-date/"] [unique_id "ajCyQ_C2Xs1VMQlhsgarJAAAAiQ"]
[Mon Jun 15 20:17:39.114979 2026] [security2:error] [pid 51003:tid 51186] [client 110.249.201.202:57886] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "webiknows.com"] [uri "/robots.txt"] [unique_id "ajCyQ8psKyvb75pkSvaPPgAAAcQ"]
[Mon Jun 15 20:17:39.162973 2026] [security2:error] [pid 53359:tid 53512] [client 57.141.14.40:41002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyQ_C2Xs1VMQlhsgarJQACJRo"]
[Mon Jun 15 20:17:39.483700 2026] [security2:error] [pid 53359:tid 53610] [client 65.111.29.77:15665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.29.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rajunandkardeputycollector.blog"] [uri "/wp-login.php"] [unique_id "ajCyQ_C2Xs1VMQlhsgarLwAAAoc"], referer: https://rajunandkardeputycollector.blog/wp-login.php
[Mon Jun 15 20:17:39.649156 2026] [security2:error] [pid 53359:tid 53567] [client 57.141.14.106:64105] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "majividyarthikes.com"] [uri "/index.php"] [unique_id "ajCyQ_C2Xs1VMQlhsgarLgACXEE"]
[Mon Jun 15 20:17:39.817257 2026] [security2:error] [pid 51003:tid 51235] [client 65.111.30.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.procrastinatingworker.imcorp.in"] [uri "/index.php"] [unique_id "ajCyQ8psKyvb75pkSvaPTgAAAfU"]
[Mon Jun 15 20:17:40.181092 2026] [security2:error] [pid 53359:tid 53442] [remote 176.129.57.20:56163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.57.129.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ukshopfronts.co.uk"] [uri "/wp-login.php"] [unique_id "ajCyRPC2Xs1VMQlhsgarSAACR0w"]
[Mon Jun 15 20:17:40.324371 2026] [security2:error] [pid 51003:tid 51173] [client 57.141.14.12:48968] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyRMpsKyvb75pkSvaPUwABtx8"]
[Mon Jun 15 20:17:40.393763 2026] [security2:error] [pid 53359:tid 53621] [client 103.125.146.49:26087] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/themes/theme-check/main.php"] [unique_id "ajCyRPC2Xs1VMQlhsgarTAAAApI"]
[Mon Jun 15 20:17:40.482064 2026] [security2:error] [pid 53359:tid 53439] [remote 176.129.57.20:56163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.57.129.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ukshopfronts.co.uk"] [uri "/wp-login.php"] [unique_id "ajCyRPC2Xs1VMQlhsgarUQACSEk"], referer: https://ukshopfronts.co.uk/wp-login.php
[Mon Jun 15 20:17:40.623891 2026] [security2:error] [pid 51003:tid 51016] [remote 121.200.216.55:55844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilsonoverseas.com"] [uri "/wp-login.php"] [unique_id "ajCyRMpsKyvb75pkSvaPWQABmQw"]
[Mon Jun 15 20:17:40.656691 2026] [security2:error] [pid 53359:tid 53566] [client 57.141.14.73:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aarohiarts.org"] [uri "/index.php"] [unique_id "ajCyRPC2Xs1VMQlhsgarTgAAAls"]
[Mon Jun 15 20:17:40.786926 2026] [lsapi:error] [pid 53359:tid 53603] [client 57.141.14.90:0] [host kthemani.com] Error on sending request(GET /en/products/1706026/ HTTP/1.1); uri(/index.php) content-length(0): ReceiveAckHdr: nothing to read from backend (LVE ID 1402; user ID 1402), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html
[Mon Jun 15 20:17:41.018864 2026] [security2:error] [pid 53359:tid 53533] [client 103.125.146.50:56579] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-admin/js/widgets/maint/"] [unique_id "ajCyRfC2Xs1VMQlhsgarWAAAAjo"]
[Mon Jun 15 20:17:41.082430 2026] [security2:error] [pid 51003:tid 51078] [remote 121.200.216.55:55844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilsonoverseas.com"] [uri "/wp-login.php"] [unique_id "ajCyRcpsKyvb75pkSvaPYwACCEo"], referer: https://wilsonoverseas.com/wp-login.php
[Mon Jun 15 20:17:41.166243 2026] [security2:error] [pid 51003:tid 51103] [remote 111.225.149.93:19870] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.puzzleadventureguide.com"] [uri "/fr/le-prince"] [unique_id "ajCyRcpsKyvb75pkSvaPZAAB02M"]
[Mon Jun 15 20:17:41.332674 2026] [security2:error] [pid 53359:tid 53580] [client 57.141.14.37:58866] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "majividyarthikes.com"] [uri "/index.php"] [unique_id "ajCyRfC2Xs1VMQlhsgarWQACaS4"]
[Mon Jun 15 20:17:41.400134 2026] [security2:error] [pid 53359:tid 53557] [client 103.125.146.79:28039] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/files/"] [unique_id "ajCyRfC2Xs1VMQlhsgarYgAAAlI"]
[Mon Jun 15 20:17:41.591651 2026] [security2:error] [pid 53359:tid 53509] [client 47.79.200.188:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "db.geeksinsight.com"] [uri "/index.php"] [unique_id "ajCyRfC2Xs1VMQlhsgaragAAAiI"], referer: https://www.google.com/
[Mon Jun 15 20:17:41.644502 2026] [security2:error] [pid 53359:tid 53598] [client 57.141.14.6:45996] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyRfC2Xs1VMQlhsgaraQACe0I"]
[Mon Jun 15 20:17:41.815049 2026] [security2:error] [pid 51003:tid 51243] [client 103.125.146.48:56835] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/ahax.php"] [unique_id "ajCyRcpsKyvb75pkSvaPdQAAAf0"]
[Mon Jun 15 20:17:41.988676 2026] [security2:error] [pid 53359:tid 53555] [client 47.79.198.130:36098] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.diggysguide.com"] [uri "/index.php"] [unique_id "ajCyRfC2Xs1VMQlhsgarcQAAAlA"]
[Mon Jun 15 20:17:42.010302 2026] [security2:error] [pid 53359:tid 53591] [client 45.84.107.172:445] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "gamergreatness.com"] [uri "/index.php"] [unique_id "ajCyRfC2Xs1VMQlhsgarbgACdGk"], referer: https://gamergreatness.com/contact
[Mon Jun 15 20:17:42.189131 2026] [security2:error] [pid 51003:tid 51236] [client 103.125.146.67:49483] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/bless.php"] [unique_id "ajCyRspsKyvb75pkSvaPgwAAAfY"]
[Mon Jun 15 20:17:42.195320 2026] [security2:error] [pid 51003:tid 51017] [remote 110.249.201.159:49862] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "thelegalites.co.in"] [uri "/wp-content/uploads/2025/11/Unlocking-Potential-Ensuring-Educational-Equity-for-Transgender-Students-DR.-Atul-Dhruv-Vol.-1-Issue-2-Sl.-9.pdf"] [unique_id "ajCyRspsKyvb75pkSvaPhAAB8Q0"]
[Mon Jun 15 20:17:42.298591 2026] [core:error] [pid 53359:tid 53508] [client 102.141.45.30:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jun 15 20:17:42.298610 2026] [core:error] [pid 53359:tid 53508] [client 102.141.45.30:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jun 15 20:17:42.589863 2026] [security2:error] [pid 53359:tid 53610] [client 103.125.146.80:45195] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/css.php"] [unique_id "ajCyRvC2Xs1VMQlhsgarnAAAAoc"]
[Mon Jun 15 20:17:42.619939 2026] [security2:error] [pid 53359:tid 53366] [remote 78.46.92.235:42976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.92.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ss316pipes.com"] [uri "/wp-login.php"] [unique_id "ajCyRvC2Xs1VMQlhsgaroAACXwA"]
[Mon Jun 15 20:17:42.666000 2026] [security2:error] [pid 53359:tid 53578] [client 57.141.14.55:31810] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyRvC2Xs1VMQlhsgarlAACZ2I"]
[Mon Jun 15 20:17:42.676244 2026] [security2:error] [pid 53359:tid 53577] [client 40.77.167.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "everyads.in"] [uri "/public/index.php"] [unique_id "ajCyRvC2Xs1VMQlhsgarnwAAAmY"]
[Mon Jun 15 20:17:42.799492 2026] [autoindex:error] [pid 53359:tid 53622] [client 62.164.177.47:0] AH01276: Cannot serve directory /home4/mazacart/public_html/digital-marketing/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:17:42.846657 2026] [security2:error] [pid 51003:tid 51151] [client 31.219.209.201:65484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.209.219.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCyRspsKyvb75pkSvaPrgAAAaE"]
[Mon Jun 15 20:17:42.846814 2026] [security2:error] [pid 51003:tid 51151] [client 31.219.209.201:65484] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCyRspsKyvb75pkSvaPrgAAAaE"]
[Mon Jun 15 20:17:42.940298 2026] [security2:error] [pid 53359:tid 53370] [remote 78.46.92.235:42976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.92.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ss316pipes.com"] [uri "/wp-login.php"] [unique_id "ajCyRvC2Xs1VMQlhsgarqgACNQQ"], referer: https://ss316pipes.com/wp-login.php
[Mon Jun 15 20:17:43.011654 2026] [security2:error] [pid 51003:tid 51255] [client 103.125.146.53:21589] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/plugins/autoload_classmap.php"] [unique_id "ajCyR8psKyvb75pkSvaPtQAAAgk"]
[Mon Jun 15 20:17:43.273594 2026] [autoindex:error] [pid 53359:tid 53566] [client 62.164.177.47:0] AH01276: Cannot serve directory /home4/mazacart/public_html/digital-marketing/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:17:43.331832 2026] [security2:error] [pid 53359:tid 53496] [client 40.77.167.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "everyads.in"] [uri "/public/index.php"] [unique_id "ajCyR_C2Xs1VMQlhsgaruwAAAhU"]
[Mon Jun 15 20:17:43.410809 2026] [security2:error] [pid 51003:tid 51164] [client 103.125.146.62:23809] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/images/"] [unique_id "ajCyR8psKyvb75pkSvaPvQAAAa4"]
[Mon Jun 15 20:17:43.725295 2026] [security2:error] [pid 51003:tid 51064] [remote 57.141.14.20:32932] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rohandasgupta.com"] [uri "/index.php"] [unique_id "ajCyR8psKyvb75pkSvaPvwABzjw"]
[Mon Jun 15 20:17:43.770410 2026] [autoindex:error] [pid 53359:tid 53610] [client 62.164.177.47:0] AH01276: Cannot serve directory /home4/mazacart/public_html/digital-marketing/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:17:43.805050 2026] [security2:error] [pid 53359:tid 53562] [client 103.125.146.38:64243] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/blocks/code/"] [unique_id "ajCyR_C2Xs1VMQlhsgaryQAAAlc"]
[Mon Jun 15 20:17:44.191189 2026] [security2:error] [pid 53359:tid 53555] [client 103.125.146.51:43605] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/fonts/"] [unique_id "ajCySPC2Xs1VMQlhsgar0QAAAlA"]
[Mon Jun 15 20:17:44.462819 2026] [security2:error] [pid 53359:tid 53532] [client 47.79.201.106:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "societytodaynews.com"] [uri "/index.php"] [unique_id "ajCySPC2Xs1VMQlhsgar1AAAAjk"], referer: https://www.google.com/
[Mon Jun 15 20:17:44.601043 2026] [security2:error] [pid 53359:tid 53513] [client 103.125.146.33:37041] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/Requests/src/Exception/Transport/"] [unique_id "ajCySPC2Xs1VMQlhsgar3AAAAiY"]
[Mon Jun 15 20:17:44.847930 2026] [security2:error] [pid 51003:tid 51238] [client 66.249.79.74:45542] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "wantpg.com"] [uri "/public/index.php/in/malunda-nicosia-cyprus-539437.html"] [unique_id "ajCySMpsKyvb75pkSvaP0wAAAfg"]
[Mon Jun 15 20:17:44.905096 2026] [security2:error] [pid 53359:tid 53615] [client 49.34.115.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kthemani.com"] [uri "/index.php"] [unique_id "ajCyR_C2Xs1VMQlhsgarrgAAAow"]
[Mon Jun 15 20:17:44.928684 2026] [security2:error] [pid 51003:tid 51153] [client 57.141.14.32:39131] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCySMpsKyvb75pkSvaP0gABoxU"]
[Mon Jun 15 20:17:44.999191 2026] [security2:error] [pid 51003:tid 51236] [client 103.125.146.75:40263] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/edit.php"] [unique_id "ajCySMpsKyvb75pkSvaP2AAAAfY"]
[Mon Jun 15 20:17:45.001632 2026] [security2:error] [pid 53359:tid 53541] [client 162.214.80.21:53038] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "talkmint.com"] [uri "/wp-content/uploads/2023/11/logo.png.webp"] [unique_id "ajCySPC2Xs1VMQlhsgar5gAAAkI"]
[Mon Jun 15 20:17:45.032705 2026] [security2:error] [pid 53359:tid 53512] [client 162.214.80.21:53040] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "talkmint.com"] [uri "/wp-content/uploads/2023/11/footer-logo.png.webp"] [unique_id "ajCySfC2Xs1VMQlhsgar6AAAAiU"]
[Mon Jun 15 20:17:45.095210 2026] [security2:error] [pid 53359:tid 53557] [client 34.75.97.148:8241] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talkmint.com"] [uri "/index.php"] [unique_id "ajCyR_C2Xs1VMQlhsgarwAAAAlI"]
[Mon Jun 15 20:17:45.115513 2026] [security2:error] [pid 51003:tid 51170] [client 47.79.201.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "analyticsias.com"] [uri "/index.php"] [unique_id "ajCySMpsKyvb75pkSvaP0AAAAbQ"], referer: https://www.google.com/
[Mon Jun 15 20:17:45.138913 2026] [security2:error] [pid 53359:tid 53533] [client 47.79.207.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "societytodaynews.com"] [uri "/index.php"] [unique_id "ajCySPC2Xs1VMQlhsgar4gAAAjo"], referer: https://www.google.com/
[Mon Jun 15 20:17:45.447799 2026] [security2:error] [pid 51003:tid 51235] [client 103.125.146.69:44689] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/info.php"] [unique_id "ajCyScpsKyvb75pkSvaP4AAAAfU"]
[Mon Jun 15 20:17:45.451714 2026] [autoindex:error] [pid 53359:tid 53581] [client 43.157.22.109:0] AH01276: Cannot serve directory /home2/zxsmgcmy/public_html/usglassalu/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:17:45.848366 2026] [lsapi:error] [pid 53359:tid 53410] [remote 84.69.248.208:0] [host www.kthemani.com] Error on sending request(GET /en/products/3602404/ HTTP/2.0); uri(/index.php) content-length(0): ReceiveAckHdr: nothing to read from backend (LVE ID 1402; user ID 1402), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html
[Mon Jun 15 20:17:45.914372 2026] [security2:error] [pid 53359:tid 53517] [client 103.125.146.70:34027] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/plugins/shell/"] [unique_id "ajCySfC2Xs1VMQlhsgar_AAAAio"]
[Mon Jun 15 20:17:46.091227 2026] [security2:error] [pid 53359:tid 53446] [remote 57.141.14.90:50448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCySfC2Xs1VMQlhsgar_wACZ1A"]
[Mon Jun 15 20:17:46.128439 2026] [security2:error] [pid 53359:tid 53411] [remote 119.195.102.159:56712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.102.195.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.fab.lbc.mybluehostin.me"] [uri "/wp-login.php"] [unique_id "ajCySvC2Xs1VMQlhsgasAgACWS0"]
[Mon Jun 15 20:17:46.324075 2026] [security2:error] [pid 53359:tid 53575] [client 103.125.146.33:23211] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/system.php"] [unique_id "ajCySvC2Xs1VMQlhsgasCAAAAmQ"]
[Mon Jun 15 20:17:46.611770 2026] [security2:error] [pid 53359:tid 53429] [remote 119.195.102.159:56712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.102.195.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.fab.lbc.mybluehostin.me"] [uri "/wp-login.php"] [unique_id "ajCySvC2Xs1VMQlhsgasDQACgD8"], referer: https://mail.fab.lbc.mybluehostin.me/wp-login.php
[Mon Jun 15 20:17:46.671909 2026] [security2:error] [pid 51003:tid 51053] [remote 74.7.227.173:46630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.rentswale.ehx.czu.mybluehostin.me"] [uri "/fonts/images/js/images/css/img/admin/uploads/icon/subcategory.php"] [unique_id "ajCySspsKyvb75pkSvaQAAABzjE"], referer: https://www.rentswale.ehx.czu.mybluehostin.me/fonts/images/js/images/css/img/admin/uploads/icon/medical_eq.jpeg
[Mon Jun 15 20:17:46.720161 2026] [security2:error] [pid 53359:tid 53527] [client 103.125.146.46:47577] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/mini.php"] [unique_id "ajCySvC2Xs1VMQlhsgasFAAAAjQ"]
[Mon Jun 15 20:17:46.817165 2026] [security2:error] [pid 53359:tid 53513] [client 57.141.14.62:38662] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.smritva.co.in"] [uri "/index.php"] [unique_id "ajCySvC2Xs1VMQlhsgasDgACJk4"]
[Mon Jun 15 20:17:46.910689 2026] [security2:error] [pid 53359:tid 53378] [remote 91.146.102.43:33794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.102.146.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ektacontech.com"] [uri "/wp-login.php"] [unique_id "ajCySvC2Xs1VMQlhsgasFgACQQw"]
[Mon Jun 15 20:17:47.047490 2026] [security2:error] [pid 51003:tid 51250] [client 47.79.201.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "societytodaynews.com"] [uri "/index.php"] [unique_id "ajCySspsKyvb75pkSvaQAgAAAgQ"], referer: https://www.google.com/
[Mon Jun 15 20:17:47.109748 2026] [security2:error] [pid 51003:tid 51206] [client 103.125.146.45:36379] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/config.php"] [unique_id "ajCyS8psKyvb75pkSvaQIgAAAdg"]
[Mon Jun 15 20:17:47.175533 2026] [security2:error] [pid 53359:tid 53391] [remote 91.146.102.43:33794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.102.146.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ektacontech.com"] [uri "/wp-login.php"] [unique_id "ajCyS_C2Xs1VMQlhsgasdQACSxk"], referer: https://ektacontech.com/wp-login.php
[Mon Jun 15 20:17:47.321854 2026] [security2:error] [pid 53359:tid 53580] [client 192.140.64.94:29666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.64.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCyS_C2Xs1VMQlhsgaseAAAAmk"]
[Mon Jun 15 20:17:47.324476 2026] [security2:error] [pid 53359:tid 53580] [client 192.140.64.94:29666] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCyS_C2Xs1VMQlhsgaseAAAAmk"]
[Mon Jun 15 20:17:47.512831 2026] [security2:error] [pid 53359:tid 53610] [client 103.125.146.51:39707] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/rest-api/fields/"] [unique_id "ajCyS_C2Xs1VMQlhsgasfQAAAoc"]
[Mon Jun 15 20:17:47.608786 2026] [security2:error] [pid 51003:tid 51070] [remote 57.141.14.31:42456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyS8psKyvb75pkSvaQKwABm0I"]
[Mon Jun 15 20:17:47.763820 2026] [security2:error] [pid 53359:tid 53596] [client 185.100.87.174:58524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.87.100.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arasansoap.com"] [uri "/xmlrpc.php"] [unique_id "ajCyS_C2Xs1VMQlhsgashAAAAnk"], referer: https://arasansoap.com/
[Mon Jun 15 20:17:47.763982 2026] [security2:error] [pid 53359:tid 53596] [client 185.100.87.174:58524] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arasansoap.com"] [uri "/xmlrpc.php"] [unique_id "ajCyS_C2Xs1VMQlhsgashAAAAnk"], referer: https://arasansoap.com/
[Mon Jun 15 20:17:47.896513 2026] [security2:error] [pid 53359:tid 53530] [client 103.125.146.32:22075] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/plugins/plugin/"] [unique_id "ajCyS_C2Xs1VMQlhsgasiQAAAjc"]
[Mon Jun 15 20:17:48.117053 2026] [security2:error] [pid 51003:tid 51152] [client 216.45.44.177:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCyS8psKyvb75pkSvaQMAABomE"]
[Mon Jun 15 20:17:48.340067 2026] [security2:error] [pid 53359:tid 53513] [client 103.125.146.31:46691] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-admin/css/colors/modern/"] [unique_id "ajCyTPC2Xs1VMQlhsgasmAAAAiY"]
[Mon Jun 15 20:17:48.343641 2026] [security2:error] [pid 51003:tid 51215] [client 52.167.144.234:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.everyads.in"] [uri "/public/index.php"] [unique_id "ajCyTMpsKyvb75pkSvaQRwAAAeE"]
[Mon Jun 15 20:17:48.681098 2026] [security2:error] [pid 53359:tid 53586] [client 52.167.144.172:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "everyads.in"] [uri "/public/index.php"] [unique_id "ajCyTPC2Xs1VMQlhsgasmwAAAm8"]
[Mon Jun 15 20:17:48.750349 2026] [security2:error] [pid 53359:tid 53517] [client 103.125.146.77:44001] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/lock360.php"] [unique_id "ajCyTPC2Xs1VMQlhsgasnwAAAio"]
[Mon Jun 15 20:17:49.103925 2026] [security2:error] [pid 53359:tid 53430] [remote 57.141.14.80:50591] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyTPC2Xs1VMQlhsgaspgACHUA"]
[Mon Jun 15 20:17:49.157644 2026] [security2:error] [pid 53359:tid 53619] [client 103.125.146.78:26751] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/block-patterns/chosen.php"] [unique_id "ajCyTfC2Xs1VMQlhsgassgAAApA"]
[Mon Jun 15 20:17:49.264578 2026] [security2:error] [pid 51003:tid 51249] [client 45.3.40.51:32479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.40.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rajunandkardeputycollector.blog"] [uri "/wp-login.php"] [unique_id "ajCyTcpsKyvb75pkSvaQYgAAAgM"], referer: https://rajunandkardeputycollector.blog/wp-login.php
[Mon Jun 15 20:17:49.400951 2026] [security2:error] [pid 53359:tid 53484] [remote 2a03:2880:f806:48:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ruchini.hemani.finance"] [uri "/index.php"] [unique_id "ajCyTfC2Xs1VMQlhsgastwACYnY"]
[Mon Jun 15 20:17:49.473827 2026] [security2:error] [pid 53359:tid 53579] [client 57.141.14.95:21475] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fifthestate.agency"] [uri "/index.php"] [unique_id "ajCyTfC2Xs1VMQlhsgastAACaEk"]
[Mon Jun 15 20:17:49.586865 2026] [security2:error] [pid 51003:tid 51252] [client 103.125.146.47:51019] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/chosen.php"] [unique_id "ajCyTcpsKyvb75pkSvaQaQAAAgY"]
[Mon Jun 15 20:17:49.834032 2026] [security2:error] [pid 53359:tid 53539] [client 171.25.193.80:9720] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "gamergreatness.com"] [uri "/index.php"] [unique_id "ajCyTfC2Xs1VMQlhsgasvwACQAU"], referer: https://gamergreatness.com/feed
[Mon Jun 15 20:17:50.528988 2026] [security2:error] [pid 51003:tid 51204] [client 254.138.48.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCyTspsKyvb75pkSvaQcgAB1ns"]
[Mon Jun 15 20:17:50.588621 2026] [security2:error] [pid 51003:tid 51136] [client 110.249.202.219:57664] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nctindia.org"] [uri "/robots.txt"] [unique_id "ajCyTspsKyvb75pkSvaQfQAAAZI"]
[Mon Jun 15 20:17:50.601074 2026] [security2:error] [pid 53359:tid 53549] [client 57.141.14.73:51986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyTvC2Xs1VMQlhsgaszAACSjI"]
[Mon Jun 15 20:17:51.000362 2026] [security2:error] [pid 51003:tid 51152] [client 103.125.146.69:54959] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/plugins/Nxploited/Nx.php"] [unique_id "ajCyTspsKyvb75pkSvaQiAAAAaI"]
[Mon Jun 15 20:17:51.142854 2026] [security2:error] [pid 53359:tid 53584] [client 143.244.57.120:43314] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.surveylaya.com"] [uri "/wp-admin/includes/"] [unique_id "ajCyT_C2Xs1VMQlhsgas3gAAAm0"]
[Mon Jun 15 20:17:51.145322 2026] [security2:error] [pid 53359:tid 53525] [client 5.255.231.127:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyT_C2Xs1VMQlhsgas2wAAAjI"]
[Mon Jun 15 20:17:51.178790 2026] [security2:error] [pid 53359:tid 53578] [client 5.255.231.127:63202] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyT_C2Xs1VMQlhsgas2QACZ3I"]
[Mon Jun 15 20:17:51.333478 2026] [core:error] [pid 53359:tid 53464] [remote 2a03:2880:f800:18:::0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jun 15 20:17:51.333499 2026] [core:error] [pid 53359:tid 53464] [remote 2a03:2880:f800:18:::0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jun 15 20:17:51.344534 2026] [security2:error] [pid 53359:tid 53483] [remote 74.7.243.230:41004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shreeramsweets-co-in.xgh.ggk.mybluehostin.me"] [uri "/plugins/owl-carousel/js/css/plugins/lightgallery/js/images_scroller/plugins/lightgallery/js/owl-carousel/images/images/background/restaurant.php"] [unique_id "ajCyT_C2Xs1VMQlhsgas5gACinU"], referer: https://shreeramsweets-co-in.xgh.ggk.mybluehostin.me/plugins/owl-carousel/js/css/plugins/lightgallery/js/images_scroller/plugins/lightgallery/js/owl-carousel/images/images/background/bg1.jpg
[Mon Jun 15 20:17:51.403956 2026] [security2:error] [pid 53359:tid 53573] [client 103.125.146.69:35913] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/wp-conflg.php"] [unique_id "ajCyT_C2Xs1VMQlhsgas5wAAAmI"]
[Mon Jun 15 20:17:51.788254 2026] [security2:error] [pid 51003:tid 51183] [client 103.125.146.59:35851] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/uploads/config.php"] [unique_id "ajCyT8psKyvb75pkSvaQmgAAAcE"]
[Mon Jun 15 20:17:51.859794 2026] [security2:error] [pid 53359:tid 53473] [remote 213.171.208.62:36854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.208.171.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kgsurvey.com"] [uri "/wp-login.php"] [unique_id "ajCyT_C2Xs1VMQlhsgas7gACaGs"]
[Mon Jun 15 20:17:51.870215 2026] [security2:error] [pid 53359:tid 53545] [client 57.141.14.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aarohiarts.org"] [uri "/index.php"] [unique_id "ajCyT_C2Xs1VMQlhsgas6wAAAkY"]
[Mon Jun 15 20:17:52.157127 2026] [security2:error] [pid 53359:tid 53425] [remote 213.171.208.62:36854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.208.171.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kgsurvey.com"] [uri "/wp-login.php"] [unique_id "ajCyUPC2Xs1VMQlhsgas9wACQzs"], referer: https://kgsurvey.com/wp-login.php
[Mon Jun 15 20:17:52.205679 2026] [security2:error] [pid 51003:tid 51169] [client 103.125.146.48:55091] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/user.php"] [unique_id "ajCyUMpsKyvb75pkSvaQpgAAAbM"]
[Mon Jun 15 20:17:52.206789 2026] [security2:error] [pid 51003:tid 51146] [client 213.180.203.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyUMpsKyvb75pkSvaQpAAAAZw"]
[Mon Jun 15 20:17:52.209448 2026] [security2:error] [pid 51003:tid 51139] [client 213.180.203.26:42798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyUMpsKyvb75pkSvaQoAABlVg"]
[Mon Jun 15 20:17:52.269402 2026] [security2:error] [pid 53359:tid 53495] [client 57.141.14.97:20834] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyUPC2Xs1VMQlhsgas9QACFAg"]
[Mon Jun 15 20:17:52.343582 2026] [security2:error] [pid 53359:tid 53367] [remote 2a03:2880:f806:15:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ruchini.hemani.finance"] [uri "/index.php"] [unique_id "ajCyUPC2Xs1VMQlhsgas_gACNAE"]
[Mon Jun 15 20:17:52.607666 2026] [security2:error] [pid 53359:tid 53574] [client 103.125.146.67:36343] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/css/dist/"] [unique_id "ajCyUPC2Xs1VMQlhsgatCAAAAmM"]
[Mon Jun 15 20:17:53.000247 2026] [security2:error] [pid 53359:tid 53459] [remote 91.146.102.43:33808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.102.146.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "archresource.co"] [uri "/wp-login.php"] [unique_id "ajCyUPC2Xs1VMQlhsgatFgACkF0"]
[Mon Jun 15 20:17:53.026353 2026] [security2:error] [pid 53359:tid 53573] [client 103.125.146.78:46919] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/themes/twentynineteen/sass/site/"] [unique_id "ajCyUfC2Xs1VMQlhsgatFwAAAmI"]
[Mon Jun 15 20:17:53.225897 2026] [security2:error] [pid 53359:tid 53569] [client 57.141.14.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ektacontech.com"] [uri "/index.php"] [unique_id "ajCyUfC2Xs1VMQlhsgatHAAAAl4"]
[Mon Jun 15 20:17:53.259264 2026] [security2:error] [pid 53359:tid 53537] [client 87.250.224.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyUfC2Xs1VMQlhsgatIgAAAj4"]
[Mon Jun 15 20:17:53.259451 2026] [security2:error] [pid 53359:tid 53397] [remote 91.146.102.43:33808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.102.146.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "archresource.co"] [uri "/wp-login.php"] [unique_id "ajCyUfC2Xs1VMQlhsgatJQACIx8"], referer: https://archresource.co/wp-login.php
[Mon Jun 15 20:17:53.262429 2026] [security2:error] [pid 53359:tid 53528] [client 87.250.224.23:45712] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyUfC2Xs1VMQlhsgatHgACNXQ"]
[Mon Jun 15 20:17:53.271498 2026] [security2:error] [pid 53359:tid 53588] [client 17.22.237.168:48290] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggermint.com"] [uri "/index.php"] [unique_id "ajCyUfC2Xs1VMQlhsgatIQAAAnE"], referer: http://www.ateneofotografico.com/
[Mon Jun 15 20:17:53.360427 2026] [security2:error] [pid 53359:tid 53583] [client 31.219.209.201:49709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.209.219.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCyUfC2Xs1VMQlhsgatJwAAAmw"]
[Mon Jun 15 20:17:53.361021 2026] [security2:error] [pid 53359:tid 53583] [client 31.219.209.201:49709] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCyUfC2Xs1VMQlhsgatJwAAAmw"]
[Mon Jun 15 20:17:53.388855 2026] [security2:error] [pid 53359:tid 53562] [client 47.128.119.142:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCyUPC2Xs1VMQlhsgatEAACVxI"]
[Mon Jun 15 20:17:53.440298 2026] [security2:error] [pid 53359:tid 53513] [client 103.125.146.66:38135] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/blocks/post-comments-form/"] [unique_id "ajCyUfC2Xs1VMQlhsgatKAAAAiY"]
[Mon Jun 15 20:17:53.598235 2026] [security2:error] [pid 51003:tid 51008] [remote 57.141.14.32:37371] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyUcpsKyvb75pkSvaQvQAB1wQ"]
[Mon Jun 15 20:17:53.806285 2026] [security2:error] [pid 53359:tid 53495] [client 34.173.239.49:38432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "chicceleb.com"] [uri "/index.php"] [unique_id "ajCyUfC2Xs1VMQlhsgatLgACFGE"]
[Mon Jun 15 20:17:53.808941 2026] [security2:error] [pid 51003:tid 51221] [client 103.125.146.40:38743] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/Text/Diff/Renderer/"] [unique_id "ajCyUcpsKyvb75pkSvaQxQAAAec"]
[Mon Jun 15 20:17:53.815856 2026] [security2:error] [pid 53359:tid 53620] [client 171.25.193.80:57684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "gamergreatness.com"] [uri "/index.php"] [unique_id "ajCyUfC2Xs1VMQlhsgatKwACkSI"], referer: https://gamergreatness.com/games
[Mon Jun 15 20:17:53.822623 2026] [security2:error] [pid 53359:tid 53598] [client 57.141.14.12:34626] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "rohandasgupta.com"] [uri "/index.php"] [unique_id "ajCyUfC2Xs1VMQlhsgatMQACez8"]
[Mon Jun 15 20:17:53.895694 2026] [security2:error] [pid 51003:tid 51149] [client 207.46.13.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "everyads.in"] [uri "/public/index.php"] [unique_id "ajCyUcpsKyvb75pkSvaQxwAAAZ8"]
[Mon Jun 15 20:17:53.927761 2026] [security2:error] [pid 53359:tid 53378] [remote 104.250.209.200:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.smgl.org"] [uri "/product-category/wholesale-sterling-silver-rings/prong-setting-rings-rings/"] [unique_id "ajCyUfC2Xs1VMQlhsgatOQACUAw"], referer: http://www.baidu.org/
[Mon Jun 15 20:17:53.971799 2026] [security2:error] [pid 53359:tid 53593] [client 34.173.239.49:38432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "chicceleb.com"] [uri "/index.php"] [unique_id "ajCyUfC2Xs1VMQlhsgatNgACdis"]
[Mon Jun 15 20:17:54.171892 2026] [security2:error] [pid 53359:tid 53491] [remote 57.141.14.73:52042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.14.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wilsonoverseas.com"] [uri "/items/G437035876"] [unique_id "ajCyUvC2Xs1VMQlhsgatQAACYH0"]
[Mon Jun 15 20:17:54.223917 2026] [security2:error] [pid 51003:tid 51172] [client 103.125.146.39:47317] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/widgets/chosen.php"] [unique_id "ajCyUspsKyvb75pkSvaQzAAAAbY"]
[Mon Jun 15 20:17:54.308692 2026] [security2:error] [pid 53359:tid 53532] [client 213.180.203.110:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyUvC2Xs1VMQlhsgatRgAAAjk"]
[Mon Jun 15 20:17:54.339202 2026] [security2:error] [pid 51003:tid 51196] [client 213.180.203.110:61990] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyUspsKyvb75pkSvaQzQABzlI"]
[Mon Jun 15 20:17:54.392583 2026] [security2:error] [pid 51003:tid 51203] [client 34.173.239.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "chicceleb.com"] [uri "/index.php"] [unique_id "ajCyUspsKyvb75pkSvaQzgAAAdU"]
[Mon Jun 15 20:17:54.483430 2026] [security2:error] [pid 53359:tid 53585] [client 47.128.119.142:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCyUvC2Xs1VMQlhsgatPQACbio"], referer: https://mywordsnthoughts.com/category/lifestyle/page/64/
[Mon Jun 15 20:17:54.497620 2026] [security2:error] [pid 51003:tid 51215] [client 47.128.119.142:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCyUspsKyvb75pkSvaQygAB4U4"], referer: https://mywordsnthoughts.com/category/lifestyle/page/64/
[Mon Jun 15 20:17:54.591019 2026] [rewrite:error] [pid 53359:tid 53550] [client 47.79.198.9:6420] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:17:54.610443 2026] [security2:error] [pid 51003:tid 51230] [client 57.141.14.53:47988] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "majividyarthikes.com"] [uri "/index.php"] [unique_id "ajCyUspsKyvb75pkSvaQzwAB8Bg"]
[Mon Jun 15 20:17:54.723485 2026] [security2:error] [pid 53359:tid 53542] [client 17.22.237.168:48290] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggermint.com"] [uri "/index.php"] [unique_id "ajCyUvC2Xs1VMQlhsgatUgAAAkM"], referer: http://www.ateneofotografico.com/
[Mon Jun 15 20:17:54.885805 2026] [security2:error] [pid 51003:tid 51153] [client 47.79.207.114:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "brainstrom.org"] [uri "/index.php"] [unique_id "ajCyUspsKyvb75pkSvaQ1wABo00"], referer: https://www.google.com/
[Mon Jun 15 20:17:54.918415 2026] [security2:error] [pid 53359:tid 53460] [remote 104.155.29.73:47652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.29.155.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ariakitsol.com"] [uri "/wp-login.php"] [unique_id "ajCyUvC2Xs1VMQlhsgatWwACGV4"]
[Mon Jun 15 20:17:55.048987 2026] [rewrite:error] [pid 53359:tid 53572] [client 47.79.198.9:6420] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:17:55.087478 2026] [security2:error] [pid 53359:tid 53377] [remote 104.155.29.73:47652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.29.155.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ariakitsol.com"] [uri "/wp-login.php"] [unique_id "ajCyU_C2Xs1VMQlhsgatYQACMgs"], referer: https://ariakitsol.com/wp-login.php
[Mon Jun 15 20:17:55.124134 2026] [security2:error] [pid 53359:tid 53556] [client 103.125.146.34:33521] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/themes/neve/assets/apps/dashboard/build/"] [unique_id "ajCyU_C2Xs1VMQlhsgatZAAAAlE"]
[Mon Jun 15 20:17:55.209838 2026] [security2:error] [pid 53359:tid 53555] [client 57.141.14.36:43642] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyU_C2Xs1VMQlhsgatYwACUGw"]
[Mon Jun 15 20:17:55.465627 2026] [security2:error] [pid 51003:tid 51142] [client 213.180.203.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyU8psKyvb75pkSvaQ5AAAAZg"]
[Mon Jun 15 20:17:55.469071 2026] [security2:error] [pid 53359:tid 53593] [client 213.180.203.21:38940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyU_C2Xs1VMQlhsgataQACdiM"]
[Mon Jun 15 20:17:55.530258 2026] [security2:error] [pid 53359:tid 53550] [client 103.125.146.45:53109] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-admin/includes/admin.php"] [unique_id "ajCyU_C2Xs1VMQlhsgatewAAAks"]
[Mon Jun 15 20:17:55.578713 2026] [security2:error] [pid 53359:tid 53470] [remote 57.141.14.37:45600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fifthestate.agency"] [uri "/index.php"] [unique_id "ajCyU_C2Xs1VMQlhsgatbgACXmg"]
[Mon Jun 15 20:17:55.594145 2026] [security2:error] [pid 53359:tid 53492] [remote 143.110.183.208:58138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 208.183.110.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "celticwavessc.ie"] [uri "/wp-login.php"] [unique_id "ajCyU_C2Xs1VMQlhsgatfgACVH4"]
[Mon Jun 15 20:17:55.915132 2026] [security2:error] [pid 53359:tid 53495] [client 103.125.146.30:42879] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-admin/user/upgrade/"] [unique_id "ajCyU_C2Xs1VMQlhsgatgwAAAhQ"]
[Mon Jun 15 20:17:55.921346 2026] [rewrite:error] [pid 51003:tid 51093] [remote 47.79.197.102:4306] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:17:56.187133 2026] [rewrite:error] [pid 51003:tid 51050] [remote 47.79.197.102:4306] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:17:56.317676 2026] [security2:error] [pid 53359:tid 53554] [client 103.125.146.42:43811] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/languages/"] [unique_id "ajCyVPC2Xs1VMQlhsgatigAAAk8"]
[Mon Jun 15 20:17:56.646579 2026] [security2:error] [pid 53359:tid 53552] [client 65.111.30.222:25959] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:url. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.procrastinatingworker.imcorp.in"] [uri "/fetch"] [unique_id "ajCyVPC2Xs1VMQlhsgatkgAAAk0"]
[Mon Jun 15 20:17:56.793819 2026] [security2:error] [pid 51003:tid 51257] [client 74.7.242.129:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCyVMpsKyvb75pkSvaQ-wACC2Q"], referer: https://mywordsnthoughts.com/nira-song-from-takkar-tamil-lyrics-in-english-with-translation/
[Mon Jun 15 20:17:56.818200 2026] [security2:error] [pid 53359:tid 53579] [client 103.125.146.52:52371] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-admin/images/"] [unique_id "ajCyVPC2Xs1VMQlhsgatlgAAAmg"]
[Mon Jun 15 20:17:57.000847 2026] [security2:error] [pid 51003:tid 51205] [client 2a03:2880:f806:d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ruchini.hemani.finance"] [uri "/index.php"] [unique_id "ajCyVMpsKyvb75pkSvaRBAAB12E"]
[Mon Jun 15 20:17:57.196158 2026] [security2:error] [pid 51003:tid 51149] [client 103.125.146.75:38769] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/edit-wolf.php"] [unique_id "ajCyVcpsKyvb75pkSvaRCQAAAZ8"]
[Mon Jun 15 20:17:57.221589 2026] [security2:error] [pid 53359:tid 53615] [client 57.141.14.103:52208] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyVfC2Xs1VMQlhsgatngACjBQ"]
[Mon Jun 15 20:17:57.631024 2026] [security2:error] [pid 53359:tid 53503] [client 103.125.146.45:22895] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/js/codemirror/"] [unique_id "ajCyVfC2Xs1VMQlhsgatqwAAAhw"]
[Mon Jun 15 20:17:57.659869 2026] [security2:error] [pid 51003:tid 51089] [remote 188.166.231.216:41012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.231.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taciturban.net.in"] [uri "/wp-login.php"] [unique_id "ajCyVcpsKyvb75pkSvaREQACBFU"]
[Mon Jun 15 20:17:57.684231 2026] [security2:error] [pid 51003:tid 51188] [client 213.180.203.235:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyVcpsKyvb75pkSvaREgAAAcY"]
[Mon Jun 15 20:17:57.687140 2026] [security2:error] [pid 53359:tid 53590] [client 213.180.203.235:43684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyVfC2Xs1VMQlhsgatqQACc00"]
[Mon Jun 15 20:17:57.875154 2026] [security2:error] [pid 51003:tid 51228] [client 192.140.64.94:29912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.64.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCyVcpsKyvb75pkSvaRFQAAAe4"]
[Mon Jun 15 20:17:57.876705 2026] [security2:error] [pid 51003:tid 51228] [client 192.140.64.94:29912] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCyVcpsKyvb75pkSvaRFQAAAe4"]
[Mon Jun 15 20:17:58.038149 2026] [security2:error] [pid 53359:tid 53607] [client 103.125.146.39:54399] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/m.php"] [unique_id "ajCyVvC2Xs1VMQlhsgattQAAAoQ"]
[Mon Jun 15 20:17:58.061718 2026] [security2:error] [pid 51003:tid 51079] [remote 188.166.231.216:41012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.231.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taciturban.net.in"] [uri "/wp-login.php"] [unique_id "ajCyVspsKyvb75pkSvaRFwACDEs"], referer: https://taciturban.net.in/wp-login.php
[Mon Jun 15 20:17:58.076961 2026] [rewrite:error] [pid 53359:tid 53423] [remote 47.79.198.77:38268] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:17:58.228248 2026] [security2:error] [pid 51003:tid 51167] [client 103.76.44.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kthemani.com"] [uri "/index.php"] [unique_id "ajCyVMpsKyvb75pkSvaQ9QABsSc"]
[Mon Jun 15 20:17:58.306807 2026] [security2:error] [pid 53359:tid 53389] [remote 57.141.14.47:55982] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyVvC2Xs1VMQlhsgatugACdhc"]
[Mon Jun 15 20:17:58.324319 2026] [security2:error] [pid 51003:tid 51056] [remote 91.146.99.41:43274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.99.146.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oasishomestay.co.in"] [uri "/wp-login.php"] [unique_id "ajCyVspsKyvb75pkSvaRHAABozQ"]
[Mon Jun 15 20:17:58.333716 2026] [rewrite:error] [pid 53359:tid 53447] [remote 47.79.198.77:38268] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:17:58.349722 2026] [security2:error] [pid 53359:tid 53496] [client 207.46.13.125:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.everyads.in"] [uri "/public/index.php"] [unique_id "ajCyVvC2Xs1VMQlhsgatwAAAAhU"]
[Mon Jun 15 20:17:58.457796 2026] [security2:error] [pid 51003:tid 51174] [client 103.125.146.46:42541] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/header.php"] [unique_id "ajCyVspsKyvb75pkSvaRHwAAAbg"]
[Mon Jun 15 20:17:58.464951 2026] [security2:error] [pid 53359:tid 53388] [remote 57.141.14.73:52084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.14.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wilsonoverseas.com"] [uri "/items/G437035876"] [unique_id "ajCyVvC2Xs1VMQlhsgatyAAChxY"]
[Mon Jun 15 20:17:58.813021 2026] [security2:error] [pid 53359:tid 53603] [client 34.90.69.83:49152] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.societytodaynews.com"] [uri "/"] [unique_id "ajCyVvC2Xs1VMQlhsgat0gAAAoA"]
[Mon Jun 15 20:17:58.813104 2026] [security2:error] [pid 53359:tid 53603] [client 34.90.69.83:49152] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.societytodaynews.com"] [uri "/"] [unique_id "ajCyVvC2Xs1VMQlhsgat0gAAAoA"]
[Mon Jun 15 20:17:58.881278 2026] [security2:error] [pid 51003:tid 51182] [client 65.111.29.103:36485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.29.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rajunandkardeputycollector.blog"] [uri "/wp-login.php"] [unique_id "ajCyVspsKyvb75pkSvaRKwAAAcA"], referer: https://rajunandkardeputycollector.blog/wp-login.php
[Mon Jun 15 20:17:58.900069 2026] [security2:error] [pid 53359:tid 53390] [remote 188.166.231.216:41020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.231.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pranshuarora.in"] [uri "/wp-login.php"] [unique_id "ajCyVvC2Xs1VMQlhsgat0wACKhg"]
[Mon Jun 15 20:17:58.904699 2026] [security2:error] [pid 51003:tid 51202] [client 57.141.14.47:55988] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyVspsKyvb75pkSvaRKQAB1Fo"]
[Mon Jun 15 20:17:58.947439 2026] [security2:error] [pid 53359:tid 53620] [client 103.125.146.44:62535] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/upgrade/"] [unique_id "ajCyVvC2Xs1VMQlhsgat1QAAApE"]
[Mon Jun 15 20:17:59.006455 2026] [security2:error] [pid 51003:tid 51004] [remote 91.146.99.41:43274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.99.146.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oasishomestay.co.in"] [uri "/wp-login.php"] [unique_id "ajCyVspsKyvb75pkSvaRLgAB6AA"], referer: https://oasishomestay.co.in/wp-login.php
[Mon Jun 15 20:17:59.134341 2026] [security2:error] [pid 53359:tid 53502] [client 223.109.255.163:54446] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.diggysguide.com"] [uri "/christmas-2020/mount-everest"] [unique_id "ajCyV_C2Xs1VMQlhsgat3QAAAhs"]
[Mon Jun 15 20:17:59.134434 2026] [security2:error] [pid 53359:tid 53502] [client 223.109.255.163:54446] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.diggysguide.com"] [uri "/christmas-2020/mount-everest"] [unique_id "ajCyV_C2Xs1VMQlhsgat3QAAAhs"]
[Mon Jun 15 20:17:59.303850 2026] [security2:error] [pid 53359:tid 53442] [remote 188.166.231.216:41020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.231.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pranshuarora.in"] [uri "/wp-login.php"] [unique_id "ajCyV_C2Xs1VMQlhsgat4AACNUw"], referer: https://pranshuarora.in/wp-login.php
[Mon Jun 15 20:17:59.359819 2026] [security2:error] [pid 51003:tid 51180] [client 103.125.146.57:20221] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/t.php"] [unique_id "ajCyV8psKyvb75pkSvaRNwAAAb4"]
[Mon Jun 15 20:17:59.388515 2026] [security2:error] [pid 53359:tid 53583] [client 52.167.144.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hemani.finance"] [uri "/index.php"] [unique_id "ajCyV_C2Xs1VMQlhsgat3AAAAmw"]
[Mon Jun 15 20:17:59.815765 2026] [security2:error] [pid 53359:tid 53610] [client 103.125.146.78:30837] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/root.php"] [unique_id "ajCyV_C2Xs1VMQlhsgat7wAAAoc"]
[Mon Jun 15 20:18:00.193111 2026] [rewrite:error] [pid 53359:tid 53439] [remote 47.79.198.73:53212] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:18:00.234662 2026] [security2:error] [pid 53359:tid 53554] [client 103.125.146.50:24745] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/css/dist/edit-post/"] [unique_id "ajCyWPC2Xs1VMQlhsgat_wAAAk8"]
[Mon Jun 15 20:18:00.238466 2026] [security2:error] [pid 53359:tid 53373] [remote 74.7.227.178:52134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "softhubtechno.ehx.czu.mybluehostin.me"] [uri "/images/img/Admin/logo/images/clients/js/js/carrer.php"] [unique_id "ajCyWPC2Xs1VMQlhsgauAQACYAc"], referer: https://softhubtechno.ehx.czu.mybluehostin.me/images/img/Admin/logo/images/clients/js/js/swipe.js
[Mon Jun 15 20:18:00.459367 2026] [rewrite:error] [pid 53359:tid 53472] [remote 47.79.198.73:53212] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:18:00.668870 2026] [security2:error] [pid 53359:tid 53407] [remote 2a03:2880:f806:3f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ruchini.hemani.finance"] [uri "/index.php"] [unique_id "ajCyWPC2Xs1VMQlhsgauCgAChCk"]
[Mon Jun 15 20:18:00.695005 2026] [security2:error] [pid 53359:tid 53585] [client 103.125.146.41:38507] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/images/media/"] [unique_id "ajCyWPC2Xs1VMQlhsgauDgAAAm4"]
[Mon Jun 15 20:18:00.820452 2026] [security2:error] [pid 53359:tid 53532] [client 57.141.14.84:38406] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyWPC2Xs1VMQlhsgauDwACOUI"]
[Mon Jun 15 20:18:00.822871 2026] [security2:error] [pid 51003:tid 51068] [remote 69.12.64.48:60310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.64.12.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dsekai.com"] [uri "/wp-comments-post.php"] [unique_id "ajCyWMpsKyvb75pkSvaRTwAB1UA"], referer: https://www.dsekai.com/?p=5413
[Mon Jun 15 20:18:00.823030 2026] [security2:error] [pid 51003:tid 51203] [client 69.12.64.48:60310] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.dsekai.com"] [uri "/wp-comments-post.php"] [unique_id "ajCyWMpsKyvb75pkSvaRTwAB1UA"], referer: https://www.dsekai.com/?p=5413
[Mon Jun 15 20:18:00.841420 2026] [security2:error] [pid 51003:tid 51233] [client 195.210.114.223:35051] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "subswaymenu.com"] [uri "/wp-login.php"] [unique_id "ajCyWMpsKyvb75pkSvaRSwAAAfM"]
[Mon Jun 15 20:18:01.006814 2026] [lsapi:error] [pid 53359:tid 53579] [client 190.212.216.197:0] [host kthemani.com] Error on sending request(GET /en/products/3619393/ HTTP/1.1); uri(/index.php) content-length(0): ReceiveAckHdr: nothing to read from backend (LVE ID 1402; user ID 1402), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html
[Mon Jun 15 20:18:01.011912 2026] [security2:error] [pid 51003:tid 51147] [client 65.111.30.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.procrastinatingworker.imcorp.in"] [uri "/index.php"] [unique_id "ajCyWMpsKyvb75pkSvaRUwAAAZ0"]
[Mon Jun 15 20:18:01.026550 2026] [security2:error] [pid 51003:tid 51118] [remote 69.12.64.48:60310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.64.12.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dsekai.com"] [uri "/wp-comments-post.php"] [unique_id "ajCyWcpsKyvb75pkSvaRVwAB0nI"], referer: https://www.dsekai.com/?p=5413
[Mon Jun 15 20:18:01.026692 2026] [security2:error] [pid 51003:tid 51200] [client 69.12.64.48:60310] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.dsekai.com"] [uri "/wp-comments-post.php"] [unique_id "ajCyWcpsKyvb75pkSvaRVwAB0nI"], referer: https://www.dsekai.com/?p=5413
[Mon Jun 15 20:18:01.087270 2026] [security2:error] [pid 51003:tid 51161] [client 103.125.146.59:32683] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/config.php"] [unique_id "ajCyWcpsKyvb75pkSvaRXAAAAas"]
[Mon Jun 15 20:18:01.154224 2026] [security2:error] [pid 53359:tid 53449] [remote 74.7.227.161:50608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.shreeramsweets.co.in"] [uri "/plugins/lightgallery/js/plugins/lightgallery/js/images_scroller/images/blog/grid/images_scroller/plugins/owl-carousel/css/images/images/background/about.php"] [unique_id "ajCyWfC2Xs1VMQlhsgauGAACV1M"], referer: https://www.shreeramsweets.co.in/plugins/lightgallery/js/plugins/lightgallery/js/images_scroller/images/blog/grid/images_scroller/plugins/owl-carousel/css/images/images/background/bg1.jpg
[Mon Jun 15 20:18:01.319022 2026] [rewrite:error] [pid 53359:tid 53534] [client 47.79.198.109:34456] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:18:01.522358 2026] [security2:error] [pid 53359:tid 53560] [client 103.125.146.38:58319] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/login.php"] [unique_id "ajCyWfC2Xs1VMQlhsgauHQAAAlU"]
[Mon Jun 15 20:18:01.782613 2026] [rewrite:error] [pid 53359:tid 53595] [client 47.79.198.109:34456] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:18:01.831836 2026] [security2:error] [pid 51003:tid 51088] [remote 212.23.216.117:52678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.216.23.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vdreamsllc.com"] [uri "/wp-login.php"] [unique_id "ajCyWcpsKyvb75pkSvaRcwAB61Q"]
[Mon Jun 15 20:18:01.909658 2026] [security2:error] [pid 53359:tid 53581] [client 103.125.146.30:41435] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-admin/css/colors/modern/test2.php"] [unique_id "ajCyWfC2Xs1VMQlhsgauKwAAAmo"]
[Mon Jun 15 20:18:01.921304 2026] [core:error] [pid 51003:tid 51138] [client 46.101.19.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jun 15 20:18:01.921334 2026] [core:error] [pid 51003:tid 51138] [client 46.101.19.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jun 15 20:18:02.265029 2026] [security2:error] [pid 51003:tid 51246] [client 57.141.14.49:57011] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyWspsKyvb75pkSvaRgAACAHE"]
[Mon Jun 15 20:18:02.309461 2026] [security2:error] [pid 51003:tid 51178] [client 103.125.146.77:47629] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/blocks/shortcode/"] [unique_id "ajCyWspsKyvb75pkSvaRhAAAAbw"]
[Mon Jun 15 20:18:02.362578 2026] [security2:error] [pid 51003:tid 51008] [remote 82.223.68.64:35102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.68.223.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "esdeipy.com"] [uri "/wp-login.php"] [unique_id "ajCyWspsKyvb75pkSvaRhgABzwQ"]
[Mon Jun 15 20:18:02.599882 2026] [rewrite:error] [pid 51003:tid 51126] [remote 47.79.198.52:37756] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:18:02.658672 2026] [security2:error] [pid 51003:tid 51086] [remote 82.223.68.64:35102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.68.223.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "esdeipy.com"] [uri "/wp-login.php"] [unique_id "ajCyWspsKyvb75pkSvaRjQACBFI"], referer: https://esdeipy.com/wp-login.php
[Mon Jun 15 20:18:02.697588 2026] [security2:error] [pid 51003:tid 51047] [remote 216.73.217.151:1940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wilsonoverseas.com"] [uri "/"] [unique_id "ajCyWspsKyvb75pkSvaRjgABjys"]
[Mon Jun 15 20:18:02.714406 2026] [security2:error] [pid 51003:tid 51186] [client 103.125.146.68:52267] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/themes/twentytwentythree/patterns/"] [unique_id "ajCyWspsKyvb75pkSvaRjwAAAcQ"]
[Mon Jun 15 20:18:02.853162 2026] [rewrite:error] [pid 51003:tid 51051] [remote 47.79.198.52:37756] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:18:03.000049 2026] [security2:error] [pid 53359:tid 53588] [client 84.21.190.140:36762] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "stepbigger.com"] [uri "/wp-content/plugins/mainwp-child/readme.txt"] [unique_id "ajCyWvC2Xs1VMQlhsgauOQAAAnE"]
[Mon Jun 15 20:18:03.056551 2026] [security2:error] [pid 51003:tid 51231] [client 66.249.68.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.samanvaycommunications.com"] [uri "/index.php"] [unique_id "ajCyWspsKyvb75pkSvaRmAAAAfE"]
[Mon Jun 15 20:18:03.136449 2026] [security2:error] [pid 53359:tid 53579] [client 103.125.146.72:54635] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/widgets/"] [unique_id "ajCyW_C2Xs1VMQlhsgauPAAAAmg"]
[Mon Jun 15 20:18:03.423351 2026] [security2:error] [pid 51003:tid 51066] [remote 91.146.99.41:43282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.99.146.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arasansoap.com"] [uri "/wp-login.php"] [unique_id "ajCyW8psKyvb75pkSvaRowAB7j4"]
[Mon Jun 15 20:18:03.534882 2026] [security2:error] [pid 53359:tid 53596] [client 103.163.220.5:34741] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/PHPMailer/"] [unique_id "ajCyW_C2Xs1VMQlhsgauQwAAAnk"]
[Mon Jun 15 20:18:03.736077 2026] [security2:error] [pid 51003:tid 51038] [remote 91.146.99.41:43282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.99.146.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arasansoap.com"] [uri "/wp-login.php"] [unique_id "ajCyW8psKyvb75pkSvaRqgAB8iI"], referer: https://arasansoap.com/wp-login.php
[Mon Jun 15 20:18:03.738457 2026] [security2:error] [pid 53359:tid 53534] [client 57.141.14.29:61179] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyW_C2Xs1VMQlhsgauSwACOw4"]
[Mon Jun 15 20:18:03.807582 2026] [security2:error] [pid 53359:tid 53605] [client 57.141.14.76:41081] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "majividyarthikes.com"] [uri "/index.php"] [unique_id "ajCyW_C2Xs1VMQlhsgauRAACglw"]
[Mon Jun 15 20:18:03.916081 2026] [security2:error] [pid 53359:tid 53505] [client 31.219.209.201:45934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.209.219.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCyW_C2Xs1VMQlhsgauUQAAAh4"]
[Mon Jun 15 20:18:03.916183 2026] [security2:error] [pid 53359:tid 53505] [client 31.219.209.201:45934] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCyW_C2Xs1VMQlhsgauUQAAAh4"]
[Mon Jun 15 20:18:03.935141 2026] [security2:error] [pid 53359:tid 53512] [client 103.125.146.59:26403] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/buy.php"] [unique_id "ajCyW_C2Xs1VMQlhsgauUgAAAiU"]
[Mon Jun 15 20:18:03.994701 2026] [security2:error] [pid 53359:tid 53598] [client 57.141.14.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aarohiarts.org"] [uri "/index.php"] [unique_id "ajCyW_C2Xs1VMQlhsgauTwAAAns"]
[Mon Jun 15 20:18:04.318763 2026] [security2:error] [pid 53359:tid 53607] [client 92.124.160.154:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kthemani.com"] [uri "/index.php"] [unique_id "ajCyWvC2Xs1VMQlhsgauMwAChAA"]
[Mon Jun 15 20:18:04.342970 2026] [security2:error] [pid 53359:tid 53507] [client 103.125.146.31:64397] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/simple.php"] [unique_id "ajCyXPC2Xs1VMQlhsgauVwAAAiA"]
[Mon Jun 15 20:18:04.703975 2026] [rewrite:error] [pid 51003:tid 51101] [remote 47.79.199.101:39274] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:18:04.730220 2026] [security2:error] [pid 51003:tid 51233] [client 103.125.146.69:48795] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/blocks/rss/"] [unique_id "ajCyXMpsKyvb75pkSvaRywAAAfM"]
[Mon Jun 15 20:18:04.855587 2026] [security2:error] [pid 53359:tid 53496] [client 84.21.190.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "stepbigger.com"] [uri "/index.php"] [unique_id "ajCyXPC2Xs1VMQlhsgauYQAAAhU"]
[Mon Jun 15 20:18:04.900867 2026] [security2:error] [pid 51003:tid 51218] [client 57.141.14.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hemani.finance"] [uri "/index.php"] [unique_id "ajCyXMpsKyvb75pkSvaRwQAAAeQ"]
[Mon Jun 15 20:18:04.967885 2026] [rewrite:error] [pid 51003:tid 51035] [remote 47.79.199.101:39274] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:18:05.060825 2026] [security2:error] [pid 53359:tid 53576] [client 196.170.93.90:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "z4residency.com"] [uri "/index.php"] [unique_id "ajCyXPC2Xs1VMQlhsgauZQAAAmU"]
[Mon Jun 15 20:18:05.116408 2026] [security2:error] [pid 51003:tid 51158] [client 103.125.146.34:48873] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/uploads/login.php"] [unique_id "ajCyXcpsKyvb75pkSvaR3gAAAag"]
[Mon Jun 15 20:18:05.165033 2026] [security2:error] [pid 51003:tid 51161] [client 57.141.14.61:40928] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyXcpsKyvb75pkSvaR2AABq1U"]
[Mon Jun 15 20:18:05.179972 2026] [security2:error] [pid 51003:tid 51256] [client 57.141.14.59:32601] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rohandasgupta.com"] [uri "/index.php"] [unique_id "ajCyXMpsKyvb75pkSvaR1AACClE"]
[Mon Jun 15 20:18:05.448877 2026] [security2:error] [pid 51003:tid 51170] [client 57.141.14.82:34476] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fifthestate.agency"] [uri "/index.php"] [unique_id "ajCyXcpsKyvb75pkSvaR4QABtEs"]
[Mon Jun 15 20:18:05.612469 2026] [security2:error] [pid 51003:tid 51009] [remote 103.28.36.122:60412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.36.28.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dhaulas.com"] [uri "/wp-login.php"] [unique_id "ajCyXcpsKyvb75pkSvaR7gABqgU"]
[Mon Jun 15 20:18:05.696934 2026] [security2:error] [pid 53359:tid 53512] [client 84.21.190.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.stepbigger.com"] [uri "/index.php"] [unique_id "ajCyXfC2Xs1VMQlhsgaudwAAAiU"], referer: https://stepbigger.com/wp-content/plugins/mainwp-child/privacy-policy.txt
[Mon Jun 15 20:18:05.850889 2026] [security2:error] [pid 51003:tid 51010] [remote 78.46.92.235:54742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.92.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "azrconsulting.in"] [uri "/wp-login.php"] [unique_id "ajCyXcpsKyvb75pkSvaR9QABwAY"]
[Mon Jun 15 20:18:06.013712 2026] [security2:error] [pid 51003:tid 51159] [client 74.7.227.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCyXcpsKyvb75pkSvaR8wABqRo"], referer: https://mywordsnthoughts.com/nirmal-palazhi-malayalam-film-actor-and-mimicry-artist-best-known-for-supporting-roles/
[Mon Jun 15 20:18:06.018946 2026] [security2:error] [pid 51003:tid 51059] [remote 103.28.36.122:60412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.36.28.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dhaulas.com"] [uri "/wp-login.php"] [unique_id "ajCyXspsKyvb75pkSvaR-QABoDc"], referer: https://dhaulas.com/wp-login.php
[Mon Jun 15 20:18:06.310566 2026] [security2:error] [pid 53359:tid 53530] [client 196.170.93.90:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "z4residency.com"] [uri "/index.php"] [unique_id "ajCyXvC2Xs1VMQlhsgaugAAAAjc"]
[Mon Jun 15 20:18:06.529201 2026] [security2:error] [pid 51003:tid 51221] [client 103.125.146.59:37779] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/gk.php"] [unique_id "ajCyXspsKyvb75pkSvaSBgAAAec"]
[Mon Jun 15 20:18:06.660037 2026] [security2:error] [pid 51003:tid 51055] [remote 78.46.92.235:54742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.92.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "azrconsulting.in"] [uri "/wp-login.php"] [unique_id "ajCyXspsKyvb75pkSvaSCQAB0jM"], referer: https://azrconsulting.in/wp-login.php
[Mon Jun 15 20:18:06.662124 2026] [autoindex:error] [pid 53359:tid 53521] [client 143.244.57.120:55514] AH01276: Cannot serve directory /home3/itjbthmy/public_html/surveylaya/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:18:06.662881 2026] [security2:error] [pid 53359:tid 53521] [client 143.244.57.120:55514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.surveylaya.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCyXvC2Xs1VMQlhsgaunAAAAi4"]
[Mon Jun 15 20:18:06.791599 2026] [rewrite:error] [pid 53359:tid 53413] [remote 47.79.197.22:55052] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:18:06.927568 2026] [security2:error] [pid 53359:tid 53576] [client 103.125.146.60:29327] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/system_log.php"] [unique_id "ajCyXvC2Xs1VMQlhsgauwwAAAmU"]
[Mon Jun 15 20:18:06.980394 2026] [security2:error] [pid 51003:tid 51139] [client 57.141.14.17:28550] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyXspsKyvb75pkSvaSEgABlUA"]
[Mon Jun 15 20:18:07.045643 2026] [rewrite:error] [pid 53359:tid 53488] [remote 47.79.197.22:55052] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:18:07.087633 2026] [security2:error] [pid 51003:tid 51005] [remote 178.236.185.252:34992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.185.236.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "stepbigger.com"] [uri "/wp-login.php"] [unique_id "ajCyX8psKyvb75pkSvaSFQAByQE"]
[Mon Jun 15 20:18:07.194025 2026] [core:error] [pid 51003:tid 51209] [client 46.101.19.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.mycoimbatore.com/
[Mon Jun 15 20:18:07.194050 2026] [core:error] [pid 51003:tid 51209] [client 46.101.19.93:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.mycoimbatore.com/
[Mon Jun 15 20:18:07.314706 2026] [security2:error] [pid 51003:tid 51170] [client 103.125.146.56:25765] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/themes/news-portal/admins-dir.php"] [unique_id "ajCyX8psKyvb75pkSvaSHQAAAbQ"]
[Mon Jun 15 20:18:07.356212 2026] [security2:error] [pid 51003:tid 51015] [remote 74.7.243.250:43366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rentswale.ehx.czu.mybluehostin.me"] [uri "/css/admin/uploads/item/admin/uploads/item/css/admin/uploads/item/images/icon/js/subcategory.php"] [unique_id "ajCyX8psKyvb75pkSvaSHwABpws"], referer: https://rentswale.ehx.czu.mybluehostin.me/css/admin/uploads/item/admin/uploads/item/css/admin/uploads/item/images/icon/js/jquery.zoom.min.js
[Mon Jun 15 20:18:07.416735 2026] [rewrite:error] [pid 53359:tid 53542] [client 47.79.196.253:40392] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:18:07.497381 2026] [security2:error] [pid 51003:tid 51023] [remote 178.236.185.252:34992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.185.236.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "stepbigger.com"] [uri "/wp-login.php"] [unique_id "ajCyX8psKyvb75pkSvaSIwABohM"], referer: https://stepbigger.com/wp-login.php
[Mon Jun 15 20:18:07.539375 2026] [security2:error] [pid 51003:tid 51041] [remote 188.166.231.216:46196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.231.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mirrorbuzz.com"] [uri "/wp-login.php"] [unique_id "ajCyX8psKyvb75pkSvaSJAAB5SU"]
[Mon Jun 15 20:18:07.690700 2026] [security2:error] [pid 53359:tid 53583] [client 103.125.146.36:63951] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/blocks/media-text/"] [unique_id "ajCyX_C2Xs1VMQlhsgau2wAAAmw"]
[Mon Jun 15 20:18:07.869091 2026] [rewrite:error] [pid 53359:tid 53507] [client 47.79.196.253:40392] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:18:08.020062 2026] [security2:error] [pid 53359:tid 53447] [remote 104.236.69.218:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "techcospace.com"] [uri "/wp-login.php"] [unique_id "ajCyX_C2Xs1VMQlhsgau5AACFlE"]
[Mon Jun 15 20:18:08.020257 2026] [security2:error] [pid 53359:tid 53497] [client 104.236.69.218:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "techcospace.com"] [uri "/wp-login.php"] [unique_id "ajCyX_C2Xs1VMQlhsgau5AACFlE"]
[Mon Jun 15 20:18:08.129541 2026] [security2:error] [pid 51003:tid 51232] [client 103.125.146.49:24537] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/uploads/2025/"] [unique_id "ajCyYMpsKyvb75pkSvaSMwAAAfI"]
[Mon Jun 15 20:18:08.131470 2026] [security2:error] [pid 51003:tid 51006] [remote 188.166.231.216:46196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.231.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mirrorbuzz.com"] [uri "/wp-login.php"] [unique_id "ajCyYMpsKyvb75pkSvaSMQAB4wI"], referer: https://mirrorbuzz.com/wp-login.php
[Mon Jun 15 20:18:08.201655 2026] [security2:error] [pid 53359:tid 53520] [client 57.141.14.38:20415] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyYPC2Xs1VMQlhsgau7QACLRY"]
[Mon Jun 15 20:18:08.292915 2026] [security2:error] [pid 53359:tid 53566] [client 88.17.163.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kthemani.com"] [uri "/index.php"] [unique_id "ajCyXvC2Xs1VMQlhsgaulwAAAls"]
[Mon Jun 15 20:18:08.442948 2026] [security2:error] [pid 53359:tid 53406] [remote 2a03:2880:f806:1:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ruchini.hemani.finance"] [uri "/index.php"] [unique_id "ajCyYPC2Xs1VMQlhsgau8gACPSg"]
[Mon Jun 15 20:18:08.497746 2026] [security2:error] [pid 53359:tid 53495] [client 192.140.64.94:29512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.64.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCyYPC2Xs1VMQlhsgau9QAAAhQ"]
[Mon Jun 15 20:18:08.499298 2026] [security2:error] [pid 53359:tid 53495] [client 192.140.64.94:29512] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCyYPC2Xs1VMQlhsgau9QAAAhQ"]
[Mon Jun 15 20:18:08.562066 2026] [security2:error] [pid 51003:tid 51197] [client 47.79.206.176:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "brainstrom.org"] [uri "/index.php"] [unique_id "ajCyYMpsKyvb75pkSvaSPwABzxU"], referer: https://www.google.com/
[Mon Jun 15 20:18:08.635188 2026] [security2:error] [pid 51003:tid 51145] [client 104.207.59.171:34645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.59.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rajunandkardeputycollector.blog"] [uri "/wp-login.php"] [unique_id "ajCyYMpsKyvb75pkSvaSQgAAAZs"], referer: https://rajunandkardeputycollector.blog/wp-login.php
[Mon Jun 15 20:18:08.743578 2026] [rewrite:error] [pid 53359:tid 53431] [remote 47.79.197.45:65180] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:18:08.784277 2026] [security2:error] [pid 51003:tid 51108] [remote 57.141.14.51:56076] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fifthestate.agency"] [uri "/index.php"] [unique_id "ajCyYMpsKyvb75pkSvaSQAACB2g"]
[Mon Jun 15 20:18:09.008987 2026] [rewrite:error] [pid 53359:tid 53438] [remote 47.79.197.45:65180] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:18:09.169477 2026] [security2:error] [pid 53359:tid 53523] [client 45.3.37.63:9113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.37.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rajunandkardeputycollector.blog"] [uri "/wp-login.php"] [unique_id "ajCyYfC2Xs1VMQlhsgavBgAAAjA"], referer: https://rajunandkardeputycollector.blog/wp-login.php
[Mon Jun 15 20:18:09.240195 2026] [security2:error] [pid 51003:tid 51177] [client 162.214.80.21:56160] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "talkmint.com"] [uri "/wp-content/uploads/2023/11/logo.png.webp"] [unique_id "ajCyYcpsKyvb75pkSvaSTQAAAbs"]
[Mon Jun 15 20:18:09.258978 2026] [security2:error] [pid 51003:tid 51198] [client 162.214.80.21:56174] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "talkmint.com"] [uri "/wp-content/uploads/2023/11/footer-logo.png.webp"] [unique_id "ajCyYcpsKyvb75pkSvaSUAAAAdA"]
[Mon Jun 15 20:18:09.309410 2026] [security2:error] [pid 53359:tid 53542] [client 35.237.11.70:23043] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talkmint.com"] [uri "/index.php"] [unique_id "ajCyYfC2Xs1VMQlhsgavAgAAAkM"]
[Mon Jun 15 20:18:09.371962 2026] [security2:error] [pid 51003:tid 51249] [client 57.141.14.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "blogliterati.com"] [uri "/index.php"] [unique_id "ajCyYcpsKyvb75pkSvaSTwAAAgM"]
[Mon Jun 15 20:18:09.590957 2026] [security2:error] [pid 53359:tid 53564] [client 103.125.146.63:40629] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/Requests/src/Exception/"] [unique_id "ajCyYfC2Xs1VMQlhsgavEAAAAlk"]
[Mon Jun 15 20:18:09.853931 2026] [security2:error] [pid 53359:tid 53559] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "stepbigger.com"] [uri "/index.php"] [unique_id "ajCyYfC2Xs1VMQlhsgavGAAAAlQ"]
[Mon Jun 15 20:18:09.855406 2026] [security2:error] [pid 53359:tid 53407] [remote 82.223.68.64:35952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.68.223.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ispatalloy.com"] [uri "/wp-login.php"] [unique_id "ajCyYfC2Xs1VMQlhsgavIwACNyk"]
[Mon Jun 15 20:18:09.912287 2026] [security2:error] [pid 53359:tid 53554] [client 57.141.14.73:36500] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyYfC2Xs1VMQlhsgavHAACT1Y"]
[Mon Jun 15 20:18:09.999376 2026] [security2:error] [pid 51003:tid 51211] [client 103.163.220.5:24571] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "ajCyYcpsKyvb75pkSvaSZQAAAd0"]
[Mon Jun 15 20:18:10.162865 2026] [security2:error] [pid 53359:tid 53416] [remote 82.223.68.64:35952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.68.223.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ispatalloy.com"] [uri "/wp-login.php"] [unique_id "ajCyYvC2Xs1VMQlhsgavLAACQTI"], referer: https://ispatalloy.com/wp-login.php
[Mon Jun 15 20:18:10.179800 2026] [security2:error] [pid 53359:tid 53523] [client 65.111.30.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.procrastinatingworker.imcorp.in"] [uri "/index.php"] [unique_id "ajCyYvC2Xs1VMQlhsgavKwAAAjA"]
[Mon Jun 15 20:18:10.339455 2026] [security2:error] [pid 51003:tid 51154] [client 74.7.227.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCyYspsKyvb75pkSvaSZgABpG8"], referer: https://mywordsnthoughts.com/nirmal-palazhi-malayalam-film-actor-and-mimicry-artist-best-known-for-supporting-roles/
[Mon Jun 15 20:18:10.573480 2026] [security2:error] [pid 51003:tid 51233] [client 82.102.18.190:36418] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ektagroup.org"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ajCyYspsKyvb75pkSvaScAAAAfM"]
[Mon Jun 15 20:18:10.659516 2026] [security2:error] [pid 53359:tid 53556] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.stepbigger.com"] [uri "/index.php"] [unique_id "ajCyYvC2Xs1VMQlhsgavMwAAAlE"]
[Mon Jun 15 20:18:10.833888 2026] [security2:error] [pid 53359:tid 53520] [client 103.125.146.37:64511] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "ajCyYvC2Xs1VMQlhsgavOQAAAi0"]
[Mon Jun 15 20:18:10.868721 2026] [rewrite:error] [pid 51003:tid 51069] [remote 47.79.199.40:60388] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:18:10.914538 2026] [security2:error] [pid 51003:tid 51104] [remote 176.61.149.165:48388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.149.61.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "chicceleb.com"] [uri "/wp-login.php"] [unique_id "ajCyYspsKyvb75pkSvaSfAABr2Q"]
[Mon Jun 15 20:18:10.935909 2026] [security2:error] [pid 51003:tid 51101] [remote 50.87.144.169:16400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.144.87.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tripuy.com"] [uri "/wp-login.php"] [unique_id "ajCyYspsKyvb75pkSvaSfgABkGE"]
[Mon Jun 15 20:18:10.970144 2026] [security2:error] [pid 53359:tid 53579] [client 87.250.224.214:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyYvC2Xs1VMQlhsgavQAAAAmg"]
[Mon Jun 15 20:18:10.973030 2026] [security2:error] [pid 53359:tid 53532] [client 87.250.224.214:60982] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyYvC2Xs1VMQlhsgavOAACORw"]
[Mon Jun 15 20:18:11.134064 2026] [rewrite:error] [pid 51003:tid 51063] [remote 47.79.199.40:60388] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:18:11.188630 2026] [lsapi:error] [pid 53359:tid 53486] [remote 84.51.217.193:0] [host www.kthemani.com] Error on sending request(GET /en/products/3697248/ HTTP/2.0); uri(/index.php) content-length(0): ReceiveAckHdr: nothing to read from backend (LVE ID 1402; user ID 1402), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html
[Mon Jun 15 20:18:11.785865 2026] [security2:error] [pid 51003:tid 51085] [remote 176.61.149.165:48388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.149.61.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "chicceleb.com"] [uri "/wp-login.php"] [unique_id "ajCyY8psKyvb75pkSvaSlgACDFE"], referer: https://chicceleb.com/wp-login.php
[Mon Jun 15 20:18:11.790074 2026] [security2:error] [pid 53359:tid 53568] [client 103.125.146.41:28583] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/blocks/gallery/"] [unique_id "ajCyY_C2Xs1VMQlhsgavkwAAAl0"]
[Mon Jun 15 20:18:11.806431 2026] [security2:error] [pid 53359:tid 53608] [client 82.102.18.190:24447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ektagroup.org"] [uri "/xmlrpc.php"] [unique_id "ajCyY_C2Xs1VMQlhsgavkgAAAoU"]
[Mon Jun 15 20:18:11.810022 2026] [autoindex:error] [pid 53359:tid 53533] [client 208.84.101.17:32110] AH01276: Cannot serve directory /home1/rugqjjmy/public_html/simmonsbankusa/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:18:11.965680 2026] [security2:error] [pid 51003:tid 51138] [client 57.141.14.56:48670] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyY8psKyvb75pkSvaSmQABlE8"]
[Mon Jun 15 20:18:12.210318 2026] [security2:error] [pid 51003:tid 51250] [client 103.125.146.49:39959] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-admin/class.php"] [unique_id "ajCyZMpsKyvb75pkSvaSrgAAAgQ"]
[Mon Jun 15 20:18:12.251553 2026] [security2:error] [pid 51003:tid 51215] [client 95.108.213.167:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyZMpsKyvb75pkSvaSrQAAAeE"]
[Mon Jun 15 20:18:12.259736 2026] [security2:error] [pid 51003:tid 51199] [client 95.108.213.167:56814] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyY8psKyvb75pkSvaSogAB0W0"]
[Mon Jun 15 20:18:12.291605 2026] [security2:error] [pid 51003:tid 51189] [client 2a03:2880:f806:40:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ruchini.hemani.finance"] [uri "/index.php"] [unique_id "ajCyZMpsKyvb75pkSvaSqAABx1w"]
[Mon Jun 15 20:18:12.308482 2026] [security2:error] [pid 51003:tid 51119] [remote 82.165.2.98:41668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.2.165.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "norplexqatar.com"] [uri "/wp-login.php"] [unique_id "ajCyZMpsKyvb75pkSvaStQABpHM"]
[Mon Jun 15 20:18:12.544195 2026] [security2:error] [pid 51003:tid 51010] [remote 57.141.14.63:37736] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fifthestate.agency"] [uri "/index.php"] [unique_id "ajCyZMpsKyvb75pkSvaSuAABwAY"]
[Mon Jun 15 20:18:12.573043 2026] [security2:error] [pid 53359:tid 53417] [remote 176.61.149.165:60522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.149.61.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nctindia.org"] [uri "/wp-login.php"] [unique_id "ajCyZPC2Xs1VMQlhsgavpAACbjM"]
[Mon Jun 15 20:18:12.593282 2026] [security2:error] [pid 51003:tid 51030] [remote 82.165.2.98:41668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.2.165.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "norplexqatar.com"] [uri "/wp-login.php"] [unique_id "ajCyZMpsKyvb75pkSvaSwAABqxo"], referer: https://norplexqatar.com/wp-login.php
[Mon Jun 15 20:18:12.619510 2026] [security2:error] [pid 53359:tid 53496] [client 103.125.146.47:21927] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/blocks/spacer/"] [unique_id "ajCyZPC2Xs1VMQlhsgavpQAAAhU"]
[Mon Jun 15 20:18:12.626906 2026] [security2:error] [pid 51003:tid 51241] [client 65.111.30.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.procrastinatingworker.imcorp.in"] [uri "/index.php"] [unique_id "ajCyZMpsKyvb75pkSvaSvQAAAfs"]
[Mon Jun 15 20:18:12.649317 2026] [security2:error] [pid 51003:tid 51131] [remote 110.249.201.35:14346] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.steelsalesco.com"] [uri "/stainless-steel-pharma-fittings-supplier-manufacturer/"] [unique_id "ajCyZMpsKyvb75pkSvaSyAACAn8"]
[Mon Jun 15 20:18:12.822733 2026] [security2:error] [pid 51003:tid 51148] [client 57.141.14.51:29788] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyZMpsKyvb75pkSvaSyQABngo"]
[Mon Jun 15 20:18:12.827282 2026] [security2:error] [pid 53359:tid 53434] [remote 176.61.149.165:60522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.149.61.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nctindia.org"] [uri "/wp-login.php"] [unique_id "ajCyZPC2Xs1VMQlhsgavqQACMEQ"], referer: https://nctindia.org/wp-login.php
[Mon Jun 15 20:18:12.997774 2026] [rewrite:error] [pid 51003:tid 51057] [remote 47.79.197.45:65190] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:18:13.015464 2026] [security2:error] [pid 51003:tid 51194] [client 103.125.146.60:40829] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/js/imgareaselect/"] [unique_id "ajCyZcpsKyvb75pkSvaS1AAAAcw"]
[Mon Jun 15 20:18:13.263032 2026] [rewrite:error] [pid 51003:tid 51055] [remote 47.79.197.45:65190] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:18:13.331949 2026] [security2:error] [pid 53359:tid 53525] [client 5.255.231.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyZfC2Xs1VMQlhsgavtgAAAjI"]
[Mon Jun 15 20:18:13.334724 2026] [security2:error] [pid 53359:tid 53504] [client 5.255.231.9:55230] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyZfC2Xs1VMQlhsgavsgACHWg"]
[Mon Jun 15 20:18:13.417827 2026] [security2:error] [pid 51003:tid 51162] [client 103.125.146.68:45141] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/themes/twentytwentyfive/"] [unique_id "ajCyZcpsKyvb75pkSvaS4gAAAaw"]
[Mon Jun 15 20:18:13.617855 2026] [security2:error] [pid 53359:tid 53509] [client 34.173.239.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCyZfC2Xs1VMQlhsgavuQACIhE"]
[Mon Jun 15 20:18:13.842172 2026] [security2:error] [pid 53359:tid 53585] [client 103.125.146.50:54335] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/themes/fukasawa/inc/classes/403x.php"] [unique_id "ajCyZfC2Xs1VMQlhsgavxQAAAm4"]
[Mon Jun 15 20:18:14.249404 2026] [security2:error] [pid 53359:tid 53502] [client 103.125.146.44:57041] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/uploads/elementor/css/"] [unique_id "ajCyZvC2Xs1VMQlhsgav6gAAAhs"]
[Mon Jun 15 20:18:14.303138 2026] [core:error] [pid 53359:tid 53508] [client 208.84.101.17:15666] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jun 15 20:18:14.303167 2026] [core:error] [pid 53359:tid 53508] [client 208.84.101.17:15666] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jun 15 20:18:14.376923 2026] [security2:error] [pid 51003:tid 51213] [client 57.141.14.68:63546] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyZspsKyvb75pkSvaS7wAB32A"]
[Mon Jun 15 20:18:14.387205 2026] [security2:error] [pid 51003:tid 51197] [client 95.108.213.240:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyZspsKyvb75pkSvaS9AAAAc8"]
[Mon Jun 15 20:18:14.390814 2026] [security2:error] [pid 53359:tid 53527] [client 95.108.213.240:43582] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyZvC2Xs1VMQlhsgav7QACNBQ"]
[Mon Jun 15 20:18:14.415679 2026] [security2:error] [pid 53359:tid 53534] [client 65.111.30.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.procrastinatingworker.imcorp.in"] [uri "/index.php"] [unique_id "ajCyZvC2Xs1VMQlhsgav9gAAAjs"]
[Mon Jun 15 20:18:14.417779 2026] [security2:error] [pid 53359:tid 53389] [remote 143.110.183.208:34512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 208.183.110.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.pathtohealth.in"] [uri "/wp-login.php"] [unique_id "ajCyZvC2Xs1VMQlhsgav-QACFBc"]
[Mon Jun 15 20:18:14.436863 2026] [security2:error] [pid 53359:tid 53621] [client 31.219.209.201:51220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.209.219.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCyZvC2Xs1VMQlhsgav-wAAApI"]
[Mon Jun 15 20:18:14.446569 2026] [security2:error] [pid 53359:tid 53621] [client 31.219.209.201:51220] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCyZvC2Xs1VMQlhsgav-wAAApI"]
[Mon Jun 15 20:18:14.498789 2026] [security2:error] [pid 53359:tid 53493] [remote 119.195.102.159:39450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.102.195.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jossbiotec.com"] [uri "/wp-login.php"] [unique_id "ajCyZvC2Xs1VMQlhsgav_QAChX8"]
[Mon Jun 15 20:18:14.695130 2026] [security2:error] [pid 53359:tid 53496] [client 103.125.146.43:47171] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/blocks/comments-pagination-numbers/"] [unique_id "ajCyZvC2Xs1VMQlhsgawCQAAAhU"]
[Mon Jun 15 20:18:14.893745 2026] [security2:error] [pid 53359:tid 53431] [remote 143.110.183.208:34512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 208.183.110.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.pathtohealth.in"] [uri "/wp-login.php"] [unique_id "ajCyZvC2Xs1VMQlhsgawEQACMEE"], referer: https://mail.pathtohealth.in/wp-login.php
[Mon Jun 15 20:18:14.970634 2026] [security2:error] [pid 53359:tid 53381] [remote 119.195.102.159:39450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.102.195.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jossbiotec.com"] [uri "/wp-login.php"] [unique_id "ajCyZvC2Xs1VMQlhsgawFAACWA8"], referer: https://jossbiotec.com/wp-login.php
[Mon Jun 15 20:18:14.972403 2026] [security2:error] [pid 53359:tid 53614] [client 57.141.14.73:44810] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyZvC2Xs1VMQlhsgawDQACixg"]
[Mon Jun 15 20:18:15.110814 2026] [security2:error] [pid 51003:tid 51166] [client 103.125.146.67:38079] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/block-bindings/"] [unique_id "ajCyZ8psKyvb75pkSvaTDQAAAbA"]
[Mon Jun 15 20:18:15.200240 2026] [security2:error] [pid 53359:tid 53601] [client 208.84.101.17:15858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "simmonsbankusa.com"] [uri "/public/.env"] [unique_id "ajCyZ_C2Xs1VMQlhsgawHQAAAn4"]
[Mon Jun 15 20:18:15.201604 2026] [core:error] [pid 51003:tid 51161] [client 208.84.101.17:15708] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jun 15 20:18:15.201627 2026] [core:error] [pid 51003:tid 51161] [client 208.84.101.17:15708] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jun 15 20:18:15.201698 2026] [core:error] [pid 53359:tid 53557] [client 208.84.101.17:16350] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jun 15 20:18:15.201713 2026] [core:error] [pid 53359:tid 53557] [client 208.84.101.17:16350] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jun 15 20:18:15.201823 2026] [core:error] [pid 53359:tid 53550] [client 208.84.101.17:16362] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jun 15 20:18:15.201845 2026] [core:error] [pid 53359:tid 53528] [client 208.84.101.17:15770] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jun 15 20:18:15.201847 2026] [core:error] [pid 53359:tid 53550] [client 208.84.101.17:16362] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jun 15 20:18:15.201858 2026] [core:error] [pid 53359:tid 53528] [client 208.84.101.17:15770] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jun 15 20:18:15.210834 2026] [security2:error] [pid 51003:tid 51027] [remote 184.107.244.93:58186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.244.107.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pehelfoundation.org"] [uri "/wp-login.php"] [unique_id "ajCyZ8psKyvb75pkSvaTEgABmhc"]
[Mon Jun 15 20:18:15.301023 2026] [security2:error] [pid 53359:tid 53576] [client 208.84.101.17:15810] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "simmonsbankusa.com"] [uri "/app/.env"] [unique_id "ajCyZ_C2Xs1VMQlhsgawLwAAAmU"]
[Mon Jun 15 20:18:15.301123 2026] [security2:error] [pid 51003:tid 51153] [client 208.84.101.17:15848] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "simmonsbankusa.com"] [uri "/server/.env"] [unique_id "ajCyZ8psKyvb75pkSvaTHAAAAaM"]
[Mon Jun 15 20:18:15.301030 2026] [core:error] [pid 51003:tid 51242] [client 208.84.101.17:15916] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jun 15 20:18:15.301162 2026] [core:error] [pid 51003:tid 51242] [client 208.84.101.17:15916] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jun 15 20:18:15.301398 2026] [core:error] [pid 53359:tid 53549] [client 208.84.101.17:15784] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jun 15 20:18:15.301413 2026] [core:error] [pid 53359:tid 53549] [client 208.84.101.17:15784] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jun 15 20:18:15.303837 2026] [core:error] [pid 53359:tid 53569] [client 208.84.101.17:16346] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jun 15 20:18:15.303857 2026] [core:error] [pid 53359:tid 53569] [client 208.84.101.17:16346] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jun 15 20:18:15.304309 2026] [security2:error] [pid 53359:tid 53543] [client 208.84.101.17:15834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "simmonsbankusa.com"] [uri "/laravel/.env"] [unique_id "ajCyZ_C2Xs1VMQlhsgawOQAAAkQ"]
[Mon Jun 15 20:18:15.304903 2026] [security2:error] [pid 51003:tid 51191] [client 208.84.101.17:15796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "simmonsbankusa.com"] [uri "/.env.old"] [unique_id "ajCyZ8psKyvb75pkSvaTHQAAAck"]
[Mon Jun 15 20:18:15.307550 2026] [security2:error] [pid 53359:tid 53545] [client 208.84.101.17:15844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "simmonsbankusa.com"] [uri "/src/.env"] [unique_id "ajCyZ_C2Xs1VMQlhsgawOwAAAkY"]
[Mon Jun 15 20:18:15.403234 2026] [security2:error] [pid 53359:tid 53579] [client 208.84.101.17:15812] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "simmonsbankusa.com"] [uri "/api/.env"] [unique_id "ajCyZ_C2Xs1VMQlhsgawTAAAAmg"]
[Mon Jun 15 20:18:15.405318 2026] [core:error] [pid 51003:tid 51198] [client 208.84.101.17:15800] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jun 15 20:18:15.405413 2026] [core:error] [pid 51003:tid 51198] [client 208.84.101.17:15800] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jun 15 20:18:15.410414 2026] [security2:error] [pid 53359:tid 53568] [client 208.84.101.17:15680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "simmonsbankusa.com"] [uri "/.env"] [unique_id "ajCyZ_C2Xs1VMQlhsgawTgAAAl0"]
[Mon Jun 15 20:18:15.412198 2026] [core:error] [pid 53359:tid 53600] [client 208.84.101.17:15762] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jun 15 20:18:15.412218 2026] [core:error] [pid 53359:tid 53600] [client 208.84.101.17:15762] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jun 15 20:18:15.448403 2026] [security2:error] [pid 53359:tid 53575] [client 87.250.224.100:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyZ_C2Xs1VMQlhsgawTQAAAmQ"]
[Mon Jun 15 20:18:15.451896 2026] [security2:error] [pid 53359:tid 53420] [remote 87.250.224.100:37172] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyZ_C2Xs1VMQlhsgawRgACbDY"]
[Mon Jun 15 20:18:15.502806 2026] [security2:error] [pid 51003:tid 51025] [remote 184.107.244.93:58186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.244.107.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pehelfoundation.org"] [uri "/wp-login.php"] [unique_id "ajCyZ8psKyvb75pkSvaTLwABsxU"], referer: https://pehelfoundation.org/wp-login.php
[Mon Jun 15 20:18:15.517850 2026] [security2:error] [pid 51003:tid 51247] [client 103.125.146.73:57077] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-admin/css/colors/"] [unique_id "ajCyZ8psKyvb75pkSvaTMgAAAgE"]
[Mon Jun 15 20:18:15.546023 2026] [security2:error] [pid 51003:tid 51174] [client 66.249.68.3:39808] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.balador.in"] [uri "/index.php"] [unique_id "ajCyZ8psKyvb75pkSvaTMQAAAbg"]
[Mon Jun 15 20:18:15.729032 2026] [security2:error] [pid 53359:tid 53513] [client 52.167.144.169:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.biomass2biooil.com"] [uri "/index.php"] [unique_id "ajCyZvC2Xs1VMQlhsgav6QACJnk"]
[Mon Jun 15 20:18:15.778119 2026] [security2:error] [pid 53359:tid 53369] [remote 82.223.68.64:60768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.68.223.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ksfaction.com"] [uri "/wp-login.php"] [unique_id "ajCyZ_C2Xs1VMQlhsgawVgACfgM"]
[Mon Jun 15 20:18:15.888768 2026] [security2:error] [pid 53359:tid 53479] [remote 57.141.14.2:53173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.14.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wilsonoverseas.com"] [uri "/items/K414993537"] [unique_id "ajCyZ_C2Xs1VMQlhsgawXQACe3E"]
[Mon Jun 15 20:18:15.911409 2026] [security2:error] [pid 51003:tid 51243] [client 103.125.146.36:49019] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/users.php"] [unique_id "ajCyZ8psKyvb75pkSvaTPgAAAf0"]
[Mon Jun 15 20:18:16.005397 2026] [core:error] [pid 53359:tid 53501] [client 208.84.101.17:16238] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jun 15 20:18:16.005423 2026] [core:error] [pid 53359:tid 53501] [client 208.84.101.17:16238] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jun 15 20:18:16.037937 2026] [security2:error] [pid 53359:tid 53439] [remote 82.223.68.64:60768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.68.223.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ksfaction.com"] [uri "/wp-login.php"] [unique_id "ajCyaPC2Xs1VMQlhsgawZQACfUk"], referer: https://ksfaction.com/wp-login.php
[Mon Jun 15 20:18:16.305390 2026] [security2:error] [pid 53359:tid 53565] [client 208.84.101.17:15854] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "simmonsbankusa.com"] [uri "/web/.env"] [unique_id "ajCyaPC2Xs1VMQlhsgawcQAAAlo"]
[Mon Jun 15 20:18:16.305467 2026] [security2:error] [pid 51003:tid 51154] [client 208.84.101.17:15828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "simmonsbankusa.com"] [uri "/backend/.env"] [unique_id "ajCyaMpsKyvb75pkSvaTUAAAAaQ"]
[Mon Jun 15 20:18:16.305867 2026] [security2:error] [pid 53359:tid 53607] [client 208.84.101.17:15738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "simmonsbankusa.com"] [uri "/.env.bak"] [unique_id "ajCyaPC2Xs1VMQlhsgawcAAAAoQ"]
[Mon Jun 15 20:18:16.305883 2026] [security2:error] [pid 51003:tid 51189] [client 208.84.101.17:15722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "simmonsbankusa.com"] [uri "/.env.backup"] [unique_id "ajCyaMpsKyvb75pkSvaTTwAAAcc"]
[Mon Jun 15 20:18:16.320831 2026] [security2:error] [pid 51003:tid 51251] [client 91.92.40.172:35992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.40.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innotech.co.in"] [uri "/wp-login.php"] [unique_id "ajCyaMpsKyvb75pkSvaTTgAAAgU"]
[Mon Jun 15 20:18:16.322504 2026] [security2:error] [pid 53359:tid 53525] [client 103.125.146.74:43099] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-admin/js/widgets/admin.php"] [unique_id "ajCyaPC2Xs1VMQlhsgawcwAAAjI"]
[Mon Jun 15 20:18:16.402066 2026] [security2:error] [pid 51003:tid 51236] [client 57.141.14.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aarohiarts.org"] [uri "/index.php"] [unique_id "ajCyaMpsKyvb75pkSvaTSQAAAfY"]
[Mon Jun 15 20:18:16.527202 2026] [security2:error] [pid 53359:tid 53515] [client 57.141.14.100:35325] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyaPC2Xs1VMQlhsgawdgACKFY"]
[Mon Jun 15 20:18:16.666344 2026] [security2:error] [pid 53359:tid 53504] [client 5.255.231.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyaPC2Xs1VMQlhsgawgQAAAh0"]
[Mon Jun 15 20:18:16.668779 2026] [security2:error] [pid 53359:tid 53563] [client 5.255.231.14:55538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyaPC2Xs1VMQlhsgawewACWEI"]
[Mon Jun 15 20:18:16.713920 2026] [security2:error] [pid 51003:tid 51159] [client 103.125.146.71:59549] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-admin/css/colors/coffee/"] [unique_id "ajCyaMpsKyvb75pkSvaTXgAAAak"]
[Mon Jun 15 20:18:16.987550 2026] [security2:error] [pid 51003:tid 51205] [client 43.173.173.18:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "itdeed.com"] [uri "/demomahayogini/product/love-astrology-services-marriage-report"] [unique_id "ajCyaMpsKyvb75pkSvaTZwAAAdc"]
[Mon Jun 15 20:18:17.087726 2026] [security2:error] [pid 53359:tid 53598] [client 103.125.146.41:32151] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/Requests/library/"] [unique_id "ajCyafC2Xs1VMQlhsgawkwAAAns"]
[Mon Jun 15 20:18:17.221486 2026] [security2:error] [pid 53359:tid 53503] [client 192.34.59.164:55138] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "itdeed.com"] [uri "/demomahayogini/wp-content/uploads/2019/06/Ontario-1.jpg"] [unique_id "ajCyafC2Xs1VMQlhsgawlAAAAhw"], referer: https://itdeed.com/
[Mon Jun 15 20:18:17.244741 2026] [security2:error] [pid 53359:tid 53580] [client 182.161.73.9:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCyaPC2Xs1VMQlhsgawkgACaWA"]
[Mon Jun 15 20:18:17.244777 2026] [security2:error] [pid 53359:tid 53580] [client 182.161.73.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCyaPC2Xs1VMQlhsgawkgACaWA"]
[Mon Jun 15 20:18:17.498927 2026] [security2:error] [pid 53359:tid 53515] [client 103.125.146.45:36633] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/interactivity-api/wp-conflg.php"] [unique_id "ajCyafC2Xs1VMQlhsgawnAAAAig"]
[Mon Jun 15 20:18:17.724239 2026] [ssl:error] [pid 53359:tid 53608] [client 98.88.137.2:53247] AH02032: Hostname sh008.webhostingservices.com (default host as no SNI was provided) and hostname autoconfig.lyondellbasellcorp.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jun 15 20:18:17.925795 2026] [security2:error] [pid 53359:tid 53588] [client 103.125.146.69:23687] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/Text/Diff/"] [unique_id "ajCyafC2Xs1VMQlhsgawqwAAAnE"]
[Mon Jun 15 20:18:17.931979 2026] [security2:error] [pid 51003:tid 51128] [remote 91.146.99.41:60690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.99.146.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "theelitecreations.com"] [uri "/wp-login.php"] [unique_id "ajCyacpsKyvb75pkSvaTiwABl3w"]
[Mon Jun 15 20:18:18.122464 2026] [security2:error] [pid 51003:tid 51104] [remote 184.107.244.93:47526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.244.107.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mycoimbatore.com"] [uri "/wp-login.php"] [unique_id "ajCyaspsKyvb75pkSvaTogAB9mQ"]
[Mon Jun 15 20:18:18.186385 2026] [security2:error] [pid 51003:tid 51070] [remote 91.146.99.41:60690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.99.146.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "theelitecreations.com"] [uri "/wp-login.php"] [unique_id "ajCyaspsKyvb75pkSvaTpAACAUI"], referer: https://theelitecreations.com/wp-login.php
[Mon Jun 15 20:18:18.208658 2026] [security2:error] [pid 51003:tid 51177] [client 43.173.182.215:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itdeed.com"] [uri "/demomahayogini/index.php"] [unique_id "ajCyacpsKyvb75pkSvaTegAAAbs"], referer: https://itdeed.com/demomahayogini/product/love-astrology-services-marriage-report
[Mon Jun 15 20:18:18.234013 2026] [security2:error] [pid 51003:tid 51219] [client 57.141.14.95:22963] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fifthestate.agency"] [uri "/index.php"] [unique_id "ajCyacpsKyvb75pkSvaTiQAB5Uw"]
[Mon Jun 15 20:18:18.297768 2026] [security2:error] [pid 53359:tid 53503] [client 65.111.30.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.procrastinatingworker.imcorp.in"] [uri "/index.php"] [unique_id "ajCyavC2Xs1VMQlhsgawvwAAAhw"]
[Mon Jun 15 20:18:18.310426 2026] [security2:error] [pid 53359:tid 53558] [client 103.125.146.48:29467] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/blocks/freeform/"] [unique_id "ajCyavC2Xs1VMQlhsgaw0AAAAlM"]
[Mon Jun 15 20:18:18.389778 2026] [security2:error] [pid 51003:tid 51121] [remote 184.107.244.93:47526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.244.107.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mycoimbatore.com"] [uri "/wp-login.php"] [unique_id "ajCyaspsKyvb75pkSvaTsQABqHU"], referer: https://mycoimbatore.com/wp-login.php
[Mon Jun 15 20:18:18.615491 2026] [security2:error] [pid 53359:tid 53606] [client 110.235.130.91:57944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.130.235.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nxtal.com"] [uri "/xmlrpc.php"] [unique_id "ajCyavC2Xs1VMQlhsgaw4wAAAoM"]
[Mon Jun 15 20:18:18.615659 2026] [security2:error] [pid 53359:tid 53606] [client 110.235.130.91:57944] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nxtal.com"] [uri "/xmlrpc.php"] [unique_id "ajCyavC2Xs1VMQlhsgaw4wAAAoM"]
[Mon Jun 15 20:18:18.686973 2026] [security2:error] [pid 53359:tid 53582] [client 103.125.146.51:60245] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/js/dist/vendor/about.php"] [unique_id "ajCyavC2Xs1VMQlhsgaw5gAAAms"]
[Mon Jun 15 20:18:18.882137 2026] [security2:error] [pid 53359:tid 53541] [client 57.141.14.86:37954] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyavC2Xs1VMQlhsgaw6QACQjs"]
[Mon Jun 15 20:18:18.951174 2026] [security2:error] [pid 51003:tid 51197] [client 192.140.64.94:29656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.64.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCyaspsKyvb75pkSvaTwQAAAc8"]
[Mon Jun 15 20:18:18.952776 2026] [security2:error] [pid 51003:tid 51197] [client 192.140.64.94:29656] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCyaspsKyvb75pkSvaTwQAAAc8"]
[Mon Jun 15 20:18:19.133726 2026] [security2:error] [pid 53359:tid 53537] [client 103.125.146.57:59935] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/ws.php"] [unique_id "ajCya_C2Xs1VMQlhsgaw8wAAAj4"]
[Mon Jun 15 20:18:19.274648 2026] [security2:error] [pid 53359:tid 53559] [client 82.102.18.190:49978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ektagroup.org"] [uri "/xmlrpc.php"] [unique_id "ajCya_C2Xs1VMQlhsgaxAAAAAlQ"]
[Mon Jun 15 20:18:19.274819 2026] [security2:error] [pid 53359:tid 53559] [client 82.102.18.190:49978] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ektagroup.org"] [uri "/xmlrpc.php"] [unique_id "ajCya_C2Xs1VMQlhsgaxAAAAAlQ"]
[Mon Jun 15 20:18:19.357019 2026] [security2:error] [pid 53359:tid 53509] [client 57.141.14.61:26632] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "majividyarthikes.com"] [uri "/index.php"] [unique_id "ajCya_C2Xs1VMQlhsgaw8gACIgg"]
[Mon Jun 15 20:18:19.442425 2026] [security2:error] [pid 51003:tid 51187] [client 185.97.95.10:56482] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "itdeed.com"] [uri "/demomahayogini/wp-content/uploads/2019/06/Ontario-1.jpg"] [unique_id "ajCya8psKyvb75pkSvaT0QAAAcU"], referer: https://itdeed.com/
[Mon Jun 15 20:18:19.522219 2026] [security2:error] [pid 53359:tid 53597] [client 103.125.146.54:39283] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/ab.php"] [unique_id "ajCya_C2Xs1VMQlhsgaxCAAAAno"]
[Mon Jun 15 20:18:19.720872 2026] [security2:error] [pid 53359:tid 53403] [remote 57.141.14.67:65257] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCya_C2Xs1VMQlhsgaxCgACkCU"]
[Mon Jun 15 20:18:19.746772 2026] [security2:error] [pid 53359:tid 53512] [client 38.171.40.91:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kthemani.com"] [uri "/index.php"] [unique_id "ajCyafC2Xs1VMQlhsgawoAACJXs"]
[Mon Jun 15 20:18:19.890920 2026] [security2:error] [pid 53359:tid 53615] [client 103.125.146.35:32607] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/js/tinymce/themes/"] [unique_id "ajCya_C2Xs1VMQlhsgaxFwAAAow"]
[Mon Jun 15 20:18:20.206526 2026] [security2:error] [pid 53359:tid 53588] [client 162.214.80.21:38422] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "talkmint.com"] [uri "/wp-content/uploads/2023/11/logo.png.webp"] [unique_id "ajCybPC2Xs1VMQlhsgaxKQAAAnE"]
[Mon Jun 15 20:18:20.233407 2026] [security2:error] [pid 53359:tid 53524] [client 162.214.80.21:38426] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "talkmint.com"] [uri "/wp-content/uploads/2023/11/footer-logo.png.webp"] [unique_id "ajCybPC2Xs1VMQlhsgaxKgAAAjE"]
[Mon Jun 15 20:18:20.299830 2026] [security2:error] [pid 51003:tid 51251] [client 57.141.14.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talkmint.com"] [uri "/index.php"] [unique_id "ajCya8psKyvb75pkSvaT5AAAAgU"]
[Mon Jun 15 20:18:20.318467 2026] [security2:error] [pid 53359:tid 53597] [client 103.125.146.33:45899] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/l10n/wp-conflg.php"] [unique_id "ajCybPC2Xs1VMQlhsgaxLwAAAno"]
[Mon Jun 15 20:18:20.726164 2026] [security2:error] [pid 51003:tid 51194] [client 43.173.178.60:40142] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "itdeed.com"] [uri "/demomahayogini/wp-content/plugins/woocommerce-product-addon/backend/assets/tooltip/tooltip.css"] [unique_id "ajCybMpsKyvb75pkSvaT_AAAAcw"], referer: https://itdeed.com/demomahayogini/product/love-astrology-services-marriage-report/
[Mon Jun 15 20:18:20.740110 2026] [security2:error] [pid 51003:tid 51174] [client 103.125.146.44:47755] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/blocks/preformatted/"] [unique_id "ajCybMpsKyvb75pkSvaT_QAAAbg"]
[Mon Jun 15 20:18:20.850649 2026] [security2:error] [pid 53359:tid 53572] [client 43.172.195.156:38876] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "itdeed.com"] [uri "/demomahayogini/wp-content/plugins/woocommerce-product-addon/css/ppom-simple-popup.css"] [unique_id "ajCybPC2Xs1VMQlhsgaxRAAAAmE"], referer: https://itdeed.com/demomahayogini/product/love-astrology-services-marriage-report/
[Mon Jun 15 20:18:20.937357 2026] [security2:error] [pid 51003:tid 51059] [remote 178.93.45.90:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCybMpsKyvb75pkSvaT8gAB0Tc"], referer: https://mywordsnthoughts.com/ammadi-ammadi-song-from-desingu-raja-lyrics-in-english-with-translation/
[Mon Jun 15 20:18:20.947823 2026] [security2:error] [pid 53359:tid 53527] [client 178.93.45.90:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCybPC2Xs1VMQlhsgaxMQACNF0"], referer: https://mywordsnthoughts.com/ammadi-ammadi-song-from-desingu-raja-lyrics-in-english-with-translation/
[Mon Jun 15 20:18:21.043759 2026] [security2:error] [pid 51003:tid 51135] [client 57.141.14.3:37240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fifthestate.agency"] [uri "/index.php"] [unique_id "ajCybMpsKyvb75pkSvaT_gABkSM"]
[Mon Jun 15 20:18:21.141159 2026] [security2:error] [pid 53359:tid 53612] [client 103.125.146.70:60851] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/database.php"] [unique_id "ajCybfC2Xs1VMQlhsgaxSwAAAok"]
[Mon Jun 15 20:18:21.203158 2026] [security2:error] [pid 51003:tid 51221] [client 143.244.57.120:57616] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.surveylaya.com"] [uri "/wp-admin/"] [unique_id "ajCybcpsKyvb75pkSvaUGQAAAec"]
[Mon Jun 15 20:18:21.224736 2026] [security2:error] [pid 53359:tid 53499] [client 43.173.181.98:38932] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "itdeed.com"] [uri "/demomahayogini/wp-content/plugins/woocommerce-product-addon/css/bootstrap/bootstrap.modal.css"] [unique_id "ajCybfC2Xs1VMQlhsgaxUwAAAhg"], referer: https://itdeed.com/demomahayogini/product/love-astrology-services-marriage-report/
[Mon Jun 15 20:18:21.277135 2026] [security2:error] [pid 51003:tid 51186] [client 43.173.179.141:43312] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "itdeed.com"] [uri "/demomahayogini/wp-content/plugins/woocommerce-product-addon/css/bootstrap/bootstrap.css"] [unique_id "ajCybcpsKyvb75pkSvaUHQAAAcQ"], referer: https://itdeed.com/demomahayogini/product/love-astrology-services-marriage-report/
[Mon Jun 15 20:18:21.421481 2026] [security2:error] [pid 53359:tid 53391] [remote 103.3.247.5:17886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.247.3.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "banacombaitea.com"] [uri "/wp-login.php"] [unique_id "ajCybfC2Xs1VMQlhsgaxWgACFxk"]
[Mon Jun 15 20:18:21.833807 2026] [security2:error] [pid 53359:tid 53421] [remote 103.3.247.5:17886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.247.3.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "banacombaitea.com"] [uri "/wp-login.php"] [unique_id "ajCybfC2Xs1VMQlhsgaxcQACkDc"], referer: https://banacombaitea.com/wp-login.php
[Mon Jun 15 20:18:22.044078 2026] [security2:error] [pid 53359:tid 53603] [client 57.141.14.73:57992] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCybfC2Xs1VMQlhsgaxcgACgCM"]
[Mon Jun 15 20:18:22.439516 2026] [security2:error] [pid 53359:tid 53601] [client 40.77.167.72:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mrrhealthtech.com"] [uri "/index.php"] [unique_id "ajCya_C2Xs1VMQlhsgaw_gAAAn4"]
[Mon Jun 15 20:18:22.498773 2026] [security2:error] [pid 53359:tid 53428] [remote 203.172.89.21:47976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.89.172.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.fab.lbc.mybluehostin.me"] [uri "/wp-login.php"] [unique_id "ajCybvC2Xs1VMQlhsgaxmwACIz4"]
[Mon Jun 15 20:18:22.515821 2026] [security2:error] [pid 53359:tid 53503] [client 103.125.146.45:23403] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/uploads/classwithtostring.php"] [unique_id "ajCybvC2Xs1VMQlhsgaxngAAAhw"]
[Mon Jun 15 20:18:22.700465 2026] [security2:error] [pid 53359:tid 53578] [client 57.141.14.2:27889] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCybvC2Xs1VMQlhsgaxnwACZ3o"]
[Mon Jun 15 20:18:22.800978 2026] [security2:error] [pid 51003:tid 51099] [remote 216.73.217.151:1940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wilsonoverseas.com"] [uri "/"] [unique_id "ajCybspsKyvb75pkSvaUUQABwV8"]
[Mon Jun 15 20:18:22.809217 2026] [security2:error] [pid 51003:tid 51209] [client 192.185.4.94:48020] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "bharathanceramics.com"] [uri "/wp-login.php"] [unique_id "ajCybspsKyvb75pkSvaUTgAB2yU"], referer: https://bharathanceramics.com/wp-login.php
[Mon Jun 15 20:18:22.838162 2026] [security2:error] [pid 51003:tid 51226] [client 139.99.122.191:52220] ModSecurity: Access denied with code 406 (phase 1). Pattern match "xmlrpc\\\\.php" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "73"] [id "392331"] [rev "3"] [msg "Atomicorp.com WAF Rules: xmlrpc DOS attack"] [severity "CRITICAL"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCybspsKyvb75pkSvaUUgAAAew"]
[Mon Jun 15 20:18:22.838335 2026] [security2:error] [pid 51003:tid 51226] [client 139.99.122.191:52220] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCybspsKyvb75pkSvaUUgAAAew"]
[Mon Jun 15 20:18:22.874061 2026] [security2:error] [pid 53359:tid 53584] [client 139.99.122.191:52222] ModSecurity: Access denied with code 406 (phase 1). Pattern match "xmlrpc\\\\.php" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "73"] [id "392331"] [rev "3"] [msg "Atomicorp.com WAF Rules: xmlrpc DOS attack"] [severity "CRITICAL"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCybvC2Xs1VMQlhsgaxogAAAm0"]
[Mon Jun 15 20:18:22.874168 2026] [security2:error] [pid 53359:tid 53584] [client 139.99.122.191:52222] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCybvC2Xs1VMQlhsgaxogAAAm0"]
[Mon Jun 15 20:18:22.891555 2026] [security2:error] [pid 53359:tid 53577] [client 103.125.146.77:56983] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/a.php"] [unique_id "ajCybvC2Xs1VMQlhsgaxowAAAmY"]
[Mon Jun 15 20:18:22.939884 2026] [security2:error] [pid 51003:tid 51171] [client 139.99.122.191:52228] ModSecurity: Access denied with code 406 (phase 1). Pattern match "xmlrpc\\\\.php" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "73"] [id "392331"] [rev "3"] [msg "Atomicorp.com WAF Rules: xmlrpc DOS attack"] [severity "CRITICAL"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCybspsKyvb75pkSvaUVAAAAbU"]
[Mon Jun 15 20:18:22.940019 2026] [security2:error] [pid 51003:tid 51171] [client 139.99.122.191:52228] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCybspsKyvb75pkSvaUVAAAAbU"]
[Mon Jun 15 20:18:22.994410 2026] [security2:error] [pid 51003:tid 51150] [client 139.99.122.191:52246] ModSecurity: Access denied with code 406 (phase 1). Pattern match "xmlrpc\\\\.php" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "73"] [id "392331"] [rev "3"] [msg "Atomicorp.com WAF Rules: xmlrpc DOS attack"] [severity "CRITICAL"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCybspsKyvb75pkSvaUVgAAAaA"]
[Mon Jun 15 20:18:22.994540 2026] [security2:error] [pid 51003:tid 51150] [client 139.99.122.191:52246] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCybspsKyvb75pkSvaUVgAAAaA"]
[Mon Jun 15 20:18:23.129571 2026] [security2:error] [pid 53359:tid 53382] [remote 2a03:2880:f806:4a:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ruchini.hemani.finance"] [uri "/index.php"] [unique_id "ajCybvC2Xs1VMQlhsgaxpQACMBA"]
[Mon Jun 15 20:18:23.278260 2026] [security2:error] [pid 53359:tid 53540] [client 139.99.122.191:52292] ModSecurity: Access denied with code 406 (phase 1). Pattern match "xmlrpc\\\\.php" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "73"] [id "392331"] [rev "3"] [msg "Atomicorp.com WAF Rules: xmlrpc DOS attack"] [severity "CRITICAL"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCyb_C2Xs1VMQlhsgaxsAAAAkE"]
[Mon Jun 15 20:18:23.279806 2026] [security2:error] [pid 53359:tid 53540] [client 139.99.122.191:52292] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCyb_C2Xs1VMQlhsgaxsAAAAkE"]
[Mon Jun 15 20:18:23.319574 2026] [security2:error] [pid 53359:tid 53496] [client 103.125.146.40:30091] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-admin/xml.php"] [unique_id "ajCyb_C2Xs1VMQlhsgaxsQAAAhU"]
[Mon Jun 15 20:18:23.340504 2026] [security2:error] [pid 53359:tid 53506] [client 216.73.216.152:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "legaleye.in"] [uri "/index.php"] [unique_id "ajCyb_C2Xs1VMQlhsgaxrgAAAh8"]
[Mon Jun 15 20:18:23.513575 2026] [security2:error] [pid 53359:tid 53559] [client 201.206.191.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kthemani.com"] [uri "/index.php"] [unique_id "ajCybfC2Xs1VMQlhsgaxUgAAAlQ"]
[Mon Jun 15 20:18:23.661319 2026] [security2:error] [pid 53359:tid 53610] [client 139.99.122.191:52326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.122.99.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srinivasgorthyandco.com"] [uri "/wp-login.php"] [unique_id "ajCyb_C2Xs1VMQlhsgaxvQAAAoc"]
[Mon Jun 15 20:18:23.695402 2026] [security2:error] [pid 51003:tid 51186] [client 139.99.122.191:52338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.122.99.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srinivasgorthyandco.com"] [uri "/wp-login.php"] [unique_id "ajCyb8psKyvb75pkSvaUYQAAAcQ"]
[Mon Jun 15 20:18:23.700910 2026] [security2:error] [pid 53359:tid 53547] [client 139.99.122.191:52344] ModSecurity: Access denied with code 406 (phase 1). Pattern match "xmlrpc\\\\.php" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "73"] [id "392331"] [rev "3"] [msg "Atomicorp.com WAF Rules: xmlrpc DOS attack"] [severity "CRITICAL"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCyb_C2Xs1VMQlhsgaxvwAAAkg"]
[Mon Jun 15 20:18:23.701065 2026] [security2:error] [pid 53359:tid 53547] [client 139.99.122.191:52344] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCyb_C2Xs1VMQlhsgaxvwAAAkg"]
[Mon Jun 15 20:18:23.707190 2026] [security2:error] [pid 51003:tid 51138] [client 103.125.146.53:34083] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/config.php"] [unique_id "ajCyb8psKyvb75pkSvaUYgAAAZQ"]
[Mon Jun 15 20:18:23.744483 2026] [security2:error] [pid 53359:tid 53556] [client 139.99.122.191:52352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.122.99.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srinivasgorthyandco.com"] [uri "/wp-login.php"] [unique_id "ajCyb_C2Xs1VMQlhsgaxwAAAAlE"]
[Mon Jun 15 20:18:23.755291 2026] [security2:error] [pid 53359:tid 53531] [client 139.99.122.191:52342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.122.99.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srinivasgorthyandco.com"] [uri "/wp-login.php"] [unique_id "ajCyb_C2Xs1VMQlhsgaxwQAAAjg"]
[Mon Jun 15 20:18:23.762444 2026] [security2:error] [pid 51003:tid 51240] [client 139.99.122.191:52350] ModSecurity: Access denied with code 406 (phase 1). Pattern match "xmlrpc\\\\.php" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "73"] [id "392331"] [rev "3"] [msg "Atomicorp.com WAF Rules: xmlrpc DOS attack"] [severity "CRITICAL"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCyb8psKyvb75pkSvaUZAAAAfo"]
[Mon Jun 15 20:18:23.762554 2026] [security2:error] [pid 51003:tid 51240] [client 139.99.122.191:52350] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCyb8psKyvb75pkSvaUZAAAAfo"]
[Mon Jun 15 20:18:23.839712 2026] [security2:error] [pid 53359:tid 53504] [client 139.99.122.191:52368] ModSecurity: Access denied with code 406 (phase 1). Pattern match "xmlrpc\\\\.php" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "73"] [id "392331"] [rev "3"] [msg "Atomicorp.com WAF Rules: xmlrpc DOS attack"] [severity "CRITICAL"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCyb_C2Xs1VMQlhsgaxxgAAAh0"]
[Mon Jun 15 20:18:23.839820 2026] [security2:error] [pid 53359:tid 53504] [client 139.99.122.191:52368] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCyb_C2Xs1VMQlhsgaxxgAAAh0"]
[Mon Jun 15 20:18:23.842890 2026] [security2:error] [pid 51003:tid 51216] [client 139.99.122.191:52366] ModSecurity: Access denied with code 406 (phase 1). Pattern match "xmlrpc\\\\.php" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "73"] [id "392331"] [rev "3"] [msg "Atomicorp.com WAF Rules: xmlrpc DOS attack"] [severity "CRITICAL"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCyb8psKyvb75pkSvaUZwAAAeI"]
[Mon Jun 15 20:18:23.842992 2026] [security2:error] [pid 51003:tid 51216] [client 139.99.122.191:52366] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCyb8psKyvb75pkSvaUZwAAAeI"]
[Mon Jun 15 20:18:23.852731 2026] [security2:error] [pid 53359:tid 53614] [client 139.99.122.191:52364] ModSecurity: Access denied with code 406 (phase 1). Pattern match "xmlrpc\\\\.php" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "73"] [id "392331"] [rev "3"] [msg "Atomicorp.com WAF Rules: xmlrpc DOS attack"] [severity "CRITICAL"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCyb_C2Xs1VMQlhsgaxyAAAAos"]
[Mon Jun 15 20:18:23.852834 2026] [security2:error] [pid 53359:tid 53614] [client 139.99.122.191:52364] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCyb_C2Xs1VMQlhsgaxyAAAAos"]
[Mon Jun 15 20:18:23.858465 2026] [security2:error] [pid 51003:tid 51139] [client 139.99.122.191:52372] ModSecurity: Access denied with code 406 (phase 1). Pattern match "xmlrpc\\\\.php" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "73"] [id "392331"] [rev "3"] [msg "Atomicorp.com WAF Rules: xmlrpc DOS attack"] [severity "CRITICAL"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCyb8psKyvb75pkSvaUaAAAAZU"]
[Mon Jun 15 20:18:23.858548 2026] [security2:error] [pid 51003:tid 51139] [client 139.99.122.191:52372] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCyb8psKyvb75pkSvaUaAAAAZU"]
[Mon Jun 15 20:18:24.056167 2026] [security2:error] [pid 53359:tid 53594] [client 139.99.122.191:52390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.122.99.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srinivasgorthyandco.com"] [uri "/wp-login.php"] [unique_id "ajCycPC2Xs1VMQlhsgax0gAAAnc"]
[Mon Jun 15 20:18:24.113415 2026] [security2:error] [pid 51003:tid 51136] [client 103.125.146.54:24307] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/.well-known/"] [unique_id "ajCycMpsKyvb75pkSvaUcQAAAZI"]
[Mon Jun 15 20:18:24.447485 2026] [security2:error] [pid 51003:tid 51252] [client 57.141.14.82:51756] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCycMpsKyvb75pkSvaUeAACBmg"]
[Mon Jun 15 20:18:24.509560 2026] [security2:error] [pid 53359:tid 53514] [client 139.99.122.191:52422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.122.99.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srinivasgorthyandco.com"] [uri "/wp-login.php"] [unique_id "ajCycPC2Xs1VMQlhsgax3AAAAic"]
[Mon Jun 15 20:18:24.522582 2026] [security2:error] [pid 53359:tid 53580] [client 103.125.146.30:48503] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/module.php"] [unique_id "ajCycPC2Xs1VMQlhsgax3QAAAmk"]
[Mon Jun 15 20:18:24.572477 2026] [security2:error] [pid 53359:tid 53604] [client 139.99.122.191:52428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.122.99.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srinivasgorthyandco.com"] [uri "/wp-login.php"] [unique_id "ajCycPC2Xs1VMQlhsgax3gAAAoE"]
[Mon Jun 15 20:18:24.596827 2026] [security2:error] [pid 51003:tid 51242] [client 139.99.122.191:52440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.122.99.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srinivasgorthyandco.com"] [uri "/wp-login.php"] [unique_id "ajCycMpsKyvb75pkSvaUfgAAAfw"]
[Mon Jun 15 20:18:24.620987 2026] [security2:error] [pid 53359:tid 53570] [client 139.99.122.191:52436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.122.99.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srinivasgorthyandco.com"] [uri "/wp-login.php"] [unique_id "ajCycPC2Xs1VMQlhsgax4AAAAl8"]
[Mon Jun 15 20:18:24.641675 2026] [security2:error] [pid 51003:tid 51198] [client 139.99.122.191:52438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.122.99.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srinivasgorthyandco.com"] [uri "/wp-login.php"] [unique_id "ajCycMpsKyvb75pkSvaUgAAAAdA"]
[Mon Jun 15 20:18:24.691969 2026] [security2:error] [pid 51003:tid 51167] [client 139.99.122.191:52442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.122.99.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srinivasgorthyandco.com"] [uri "/wp-login.php"] [unique_id "ajCycMpsKyvb75pkSvaUiAAAAbE"]
[Mon Jun 15 20:18:24.911780 2026] [security2:error] [pid 51003:tid 51221] [client 103.125.146.46:61345] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/Requests/src/Auth/"] [unique_id "ajCycMpsKyvb75pkSvaUjQAAAec"]
[Mon Jun 15 20:18:25.003600 2026] [autoindex:error] [pid 51003:tid 51197] [client 162.254.36.150:0] AH01276: Cannot serve directory /home4/mazacart/public_html/digital-marketing/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:18:25.010218 2026] [security2:error] [pid 53359:tid 53539] [client 31.219.209.201:51822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.209.219.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCycfC2Xs1VMQlhsgax6AAAAkA"]
[Mon Jun 15 20:18:25.010369 2026] [security2:error] [pid 53359:tid 53539] [client 31.219.209.201:51822] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCycfC2Xs1VMQlhsgax6AAAAkA"]
[Mon Jun 15 20:18:25.155167 2026] [security2:error] [pid 51003:tid 51235] [client 139.99.122.191:52476] ModSecurity: Access denied with code 406 (phase 1). Pattern match "xmlrpc\\\\.php" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "73"] [id "392331"] [rev "3"] [msg "Atomicorp.com WAF Rules: xmlrpc DOS attack"] [severity "CRITICAL"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCyccpsKyvb75pkSvaUlgAAAfU"]
[Mon Jun 15 20:18:25.155304 2026] [security2:error] [pid 51003:tid 51235] [client 139.99.122.191:52476] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCyccpsKyvb75pkSvaUlgAAAfU"]
[Mon Jun 15 20:18:25.313192 2026] [security2:error] [pid 51003:tid 51165] [client 103.125.146.45:57221] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/theme-compat/chosen.php"] [unique_id "ajCyccpsKyvb75pkSvaUmwAAAa8"]
[Mon Jun 15 20:18:25.706185 2026] [security2:error] [pid 51003:tid 51162] [client 103.125.146.64:35493] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/blocks/post-featured-image/"] [unique_id "ajCyccpsKyvb75pkSvaUpQAAAaw"]
[Mon Jun 15 20:18:25.892278 2026] [security2:error] [pid 53359:tid 53505] [client 47.79.200.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "societytodaynews.com"] [uri "/index.php"] [unique_id "ajCycfC2Xs1VMQlhsgax9gAAAh4"], referer: https://www.google.com/
[Mon Jun 15 20:18:25.912333 2026] [security2:error] [pid 51003:tid 51194] [client 57.141.14.44:48595] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyccpsKyvb75pkSvaUpwABzGE"]
[Mon Jun 15 20:18:25.980864 2026] [security2:error] [pid 53359:tid 53590] [client 139.99.122.191:52532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.122.99.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srinivasgorthyandco.com"] [uri "/wp-login.php"] [unique_id "ajCycfC2Xs1VMQlhsgayAwAAAnM"]
[Mon Jun 15 20:18:26.108717 2026] [security2:error] [pid 53359:tid 53612] [client 254.140.90.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCycfC2Xs1VMQlhsgax_AACiVM"]
[Mon Jun 15 20:18:26.115291 2026] [autoindex:error] [pid 53359:tid 53617] [client 208.84.101.17:37328] AH01276: Cannot serve directory /home1/rugqjjmy/public_html/simmonsbankusa/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:18:26.181222 2026] [security2:error] [pid 51003:tid 51216] [client 139.99.122.191:52540] ModSecurity: Access denied with code 406 (phase 1). Pattern match "xmlrpc\\\\.php" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "73"] [id "392331"] [rev "3"] [msg "Atomicorp.com WAF Rules: xmlrpc DOS attack"] [severity "CRITICAL"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCycspsKyvb75pkSvaUrQAAAeI"]
[Mon Jun 15 20:18:26.181391 2026] [security2:error] [pid 51003:tid 51216] [client 139.99.122.191:52540] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCycspsKyvb75pkSvaUrQAAAeI"]
[Mon Jun 15 20:18:26.251216 2026] [security2:error] [pid 51003:tid 51182] [client 103.125.146.39:52381] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/themes/twentytwentytwo/templates/"] [unique_id "ajCycspsKyvb75pkSvaUsgAAAcA"]
[Mon Jun 15 20:18:26.495502 2026] [security2:error] [pid 53359:tid 53508] [client 185.243.218.231:53496] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "gamergreatness.com"] [uri "/index.php"] [unique_id "ajCycvC2Xs1VMQlhsgayDwACITA"], referer: https://gamergreatness.com/games-that-will-keep-you-sane-during-lockdown
[Mon Jun 15 20:18:26.753883 2026] [security2:error] [pid 53359:tid 53538] [client 103.125.146.60:59385] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/uploads/upload.php"] [unique_id "ajCycvC2Xs1VMQlhsgayHgAAAj8"]
[Mon Jun 15 20:18:26.937678 2026] [security2:error] [pid 51003:tid 51190] [client 85.174.183.162:17461] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "rkfreshmart.net"] [uri "/index.php"] [unique_id "ajCycspsKyvb75pkSvaUwAAAAcg"]
[Mon Jun 15 20:18:27.046315 2026] [security2:error] [pid 53359:tid 53380] [remote 82.137.41.8:52408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.41.137.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "convergenceofthoughts.org"] [uri "/wp-login.php"] [unique_id "ajCyc_C2Xs1VMQlhsgayKAACaQ4"]
[Mon Jun 15 20:18:27.080047 2026] [security2:error] [pid 53359:tid 53534] [client 139.99.122.191:52638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.122.99.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srinivasgorthyandco.com"] [uri "/wp-login.php"] [unique_id "ajCyc_C2Xs1VMQlhsgayKQAAAjs"]
[Mon Jun 15 20:18:27.215535 2026] [security2:error] [pid 51003:tid 51238] [client 103.125.146.77:38949] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-signin.php"] [unique_id "ajCyc8psKyvb75pkSvaUyQAAAfg"]
[Mon Jun 15 20:18:27.360108 2026] [security2:error] [pid 53359:tid 53598] [client 57.141.14.39:34918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyc_C2Xs1VMQlhsgayLAACe3U"]
[Mon Jun 15 20:18:27.441715 2026] [security2:error] [pid 53359:tid 53518] [client 2a03:2880:f806:3:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ruchini.hemani.finance"] [uri "/index.php"] [unique_id "ajCyc_C2Xs1VMQlhsgayNQACK2s"]
[Mon Jun 15 20:18:27.477600 2026] [security2:error] [pid 53359:tid 53425] [remote 82.137.41.8:52408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.41.137.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "convergenceofthoughts.org"] [uri "/wp-login.php"] [unique_id "ajCyc_C2Xs1VMQlhsgayOwACgDs"], referer: https://convergenceofthoughts.org/wp-login.php
[Mon Jun 15 20:18:27.655974 2026] [security2:error] [pid 53359:tid 53519] [client 147.182.162.176:54548] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "iprelief.xrq.wja.mybluehostin.me"] [uri "/wp-login.php"] [unique_id "ajCyc_C2Xs1VMQlhsgayQgAAAiw"]
[Mon Jun 15 20:18:27.804811 2026] [security2:error] [pid 53359:tid 53506] [client 208.84.101.17:37328] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "simmonsbankusa.com"] [uri "/.env.production.copy"] [unique_id "ajCyc_C2Xs1VMQlhsgayTQAAAh8"]
[Mon Jun 15 20:18:27.973050 2026] [security2:error] [pid 53359:tid 53500] [client 104.207.58.163:39377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.58.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rajunandkardeputycollector.blog"] [uri "/wp-login.php"] [unique_id "ajCyc_C2Xs1VMQlhsgayVQAAAhk"], referer: https://rajunandkardeputycollector.blog/wp-login.php
[Mon Jun 15 20:18:27.976182 2026] [security2:error] [pid 51003:tid 51186] [client 2804:3d28:45:7cd8:65fc:c814:a942:bf6c:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kthemani.com"] [uri "/index.php"] [unique_id "ajCyccpsKyvb75pkSvaUpgABxDY"]
[Mon Jun 15 20:18:27.993158 2026] [security2:error] [pid 53359:tid 53619] [client 147.182.162.176:54898] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "iprelief.xrq.wja.mybluehostin.me"] [uri "/wp-login.php"] [unique_id "ajCyc_C2Xs1VMQlhsgayVgAAApA"]
[Mon Jun 15 20:18:28.201826 2026] [security2:error] [pid 53359:tid 53513] [client 40.77.167.26:63150] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "majividyarthikes.com"] [uri "/index.php"] [unique_id "ajCyc_C2Xs1VMQlhsgayVAACJlk"]
[Mon Jun 15 20:18:28.222686 2026] [security2:error] [pid 51003:tid 51139] [client 89.124.114.167:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.yourstoreaddons.com"] [uri "/advanced-pagination.html.php"] [unique_id "ajCydMpsKyvb75pkSvaU5AAAAZU"], referer: https://www.yourstoreaddons.com/advanced-pagination.html/
[Mon Jun 15 20:18:28.417797 2026] [security2:error] [pid 51003:tid 51137] [client 126.209.47.75:58236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.47.209.126.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nxtal.com"] [uri "/xmlrpc.php"] [unique_id "ajCydMpsKyvb75pkSvaU6wAAAZM"]
[Mon Jun 15 20:18:28.418039 2026] [security2:error] [pid 51003:tid 51137] [client 126.209.47.75:58236] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nxtal.com"] [uri "/xmlrpc.php"] [unique_id "ajCydMpsKyvb75pkSvaU6wAAAZM"]
[Mon Jun 15 20:18:28.609313 2026] [core:error] [pid 53359:tid 53622] [client 208.84.101.17:37328] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jun 15 20:18:28.609340 2026] [core:error] [pid 53359:tid 53622] [client 208.84.101.17:37328] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jun 15 20:18:28.634432 2026] [security2:error] [pid 53359:tid 53596] [client 103.125.146.39:25471] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-admin/maint/network/"] [unique_id "ajCydPC2Xs1VMQlhsgayZwAAAnk"]
[Mon Jun 15 20:18:28.676890 2026] [security2:error] [pid 53359:tid 53486] [remote 185.243.218.231:53510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.218.243.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gamergreatness.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ajCydPC2Xs1VMQlhsgayagACaXg"], referer: https://gamergreatness.com/wp-admin/admin-ajax.php?action=wpdAddSubscription
[Mon Jun 15 20:18:28.698772 2026] [security2:error] [pid 51003:tid 51149] [client 47.128.119.165:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCydMpsKyvb75pkSvaU2wABnxw"]
[Mon Jun 15 20:18:28.798088 2026] [security2:error] [pid 53359:tid 53617] [client 89.124.114.167:12370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.114.124.89.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.yourstoreaddons.com"] [uri "/advanced-pagination.html.php/"] [unique_id "ajCydPC2Xs1VMQlhsgaydAAAAo4"], referer: https://www.yourstoreaddons.com/advanced-pagination.html.php/
[Mon Jun 15 20:18:28.805310 2026] [security2:error] [pid 53359:tid 53601] [client 35.204.200.243:32768] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.editonmedia.com"] [uri "/"] [unique_id "ajCydPC2Xs1VMQlhsgaydQAAAn4"]
[Mon Jun 15 20:18:28.805437 2026] [security2:error] [pid 53359:tid 53601] [client 35.204.200.243:32768] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mail.editonmedia.com"] [uri "/"] [unique_id "ajCydPC2Xs1VMQlhsgaydQAAAn4"]
[Mon Jun 15 20:18:28.884004 2026] [security2:error] [pid 51003:tid 51153] [client 57.141.14.95:54181] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCydMpsKyvb75pkSvaU8wABo3s"]
[Mon Jun 15 20:18:29.046823 2026] [security2:error] [pid 51003:tid 51190] [client 103.125.146.48:58513] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/we.php"] [unique_id "ajCydcpsKyvb75pkSvaU-gAAAcg"]
[Mon Jun 15 20:18:29.084212 2026] [security2:error] [pid 51003:tid 51208] [client 57.141.14.106:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aarohiarts.org"] [uri "/index.php"] [unique_id "ajCydMpsKyvb75pkSvaU9gAAAdo"]
[Mon Jun 15 20:18:29.208962 2026] [security2:error] [pid 53359:tid 53606] [client 208.84.101.17:37400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "simmonsbankusa.com"] [uri "/.env.copy"] [unique_id "ajCydfC2Xs1VMQlhsgaygQAAAoM"]
[Mon Jun 15 20:18:29.208961 2026] [security2:error] [pid 53359:tid 53561] [client 208.84.101.17:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "simmonsbankusa.com"] [uri "/.env.swp"] [unique_id "ajCydfC2Xs1VMQlhsgayggAAAlY"]
[Mon Jun 15 20:18:29.208961 2026] [security2:error] [pid 53359:tid 53501] [client 208.84.101.17:37368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "simmonsbankusa.com"] [uri "/.env~"] [unique_id "ajCydfC2Xs1VMQlhsgaygwAAAho"]
[Mon Jun 15 20:18:29.208961 2026] [security2:error] [pid 51003:tid 51182] [client 208.84.101.17:37420] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "simmonsbankusa.com"] [uri "/.env.local.old"] [unique_id "ajCydcpsKyvb75pkSvaVAgAAAcA"]
[Mon Jun 15 20:18:29.209939 2026] [core:error] [pid 53359:tid 53612] [client 208.84.101.17:37340] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jun 15 20:18:29.209950 2026] [core:error] [pid 53359:tid 53612] [client 208.84.101.17:37340] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jun 15 20:18:29.209950 2026] [core:error] [pid 53359:tid 53598] [client 208.84.101.17:37344] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jun 15 20:18:29.209961 2026] [core:error] [pid 53359:tid 53598] [client 208.84.101.17:37344] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jun 15 20:18:29.210072 2026] [core:error] [pid 53359:tid 53514] [client 208.84.101.17:37354] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jun 15 20:18:29.210087 2026] [core:error] [pid 53359:tid 53514] [client 208.84.101.17:37354] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jun 15 20:18:29.233577 2026] [security2:error] [pid 53359:tid 53619] [client 91.92.40.173:32842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.40.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "audiomart.in"] [uri "/wp-login.php"] [unique_id "ajCydfC2Xs1VMQlhsgayhAAAApA"]
[Mon Jun 15 20:18:29.398946 2026] [core:error] [pid 51003:tid 51230] [client 208.84.101.17:37348] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jun 15 20:18:29.398970 2026] [core:error] [pid 51003:tid 51230] [client 208.84.101.17:37348] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jun 15 20:18:29.413650 2026] [core:error] [pid 51003:tid 51245] [client 208.84.101.17:37352] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jun 15 20:18:29.413681 2026] [core:error] [pid 51003:tid 51245] [client 208.84.101.17:37352] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jun 15 20:18:29.449724 2026] [security2:error] [pid 53359:tid 53585] [client 192.140.64.94:29579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.64.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCydfC2Xs1VMQlhsgayjwAAAm4"]
[Mon Jun 15 20:18:29.449890 2026] [security2:error] [pid 53359:tid 53585] [client 192.140.64.94:29579] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCydfC2Xs1VMQlhsgayjwAAAm4"]
[Mon Jun 15 20:18:29.464502 2026] [security2:error] [pid 53359:tid 53533] [client 103.125.146.74:44335] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/js/tinymce/plugins/wp-load.php"] [unique_id "ajCydfC2Xs1VMQlhsgaykQAAAjo"]
[Mon Jun 15 20:18:29.591295 2026] [security2:error] [pid 53359:tid 53604] [client 208.84.101.17:37432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "simmonsbankusa.com"] [uri "/.env.local.backup"] [unique_id "ajCydfC2Xs1VMQlhsgaylQAAAoE"]
[Mon Jun 15 20:18:29.610385 2026] [security2:error] [pid 53359:tid 53563] [client 208.84.101.17:37546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "simmonsbankusa.com"] [uri "/.env.production.swp"] [unique_id "ajCydfC2Xs1VMQlhsgaymAAAAlg"]
[Mon Jun 15 20:18:29.708860 2026] [security2:error] [pid 51003:tid 51167] [client 208.84.101.17:37542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "simmonsbankusa.com"] [uri "/.env.production~"] [unique_id "ajCydcpsKyvb75pkSvaVEwAAAbE"]
[Mon Jun 15 20:18:29.708861 2026] [security2:error] [pid 51003:tid 51161] [client 208.84.101.17:37556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "simmonsbankusa.com"] [uri "/.env.production.orig"] [unique_id "ajCydcpsKyvb75pkSvaVEgAAAas"]
[Mon Jun 15 20:18:29.708861 2026] [security2:error] [pid 53359:tid 53549] [client 208.84.101.17:37510] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "simmonsbankusa.com"] [uri "/.env.production.old"] [unique_id "ajCydfC2Xs1VMQlhsgaymwAAAko"]
[Mon Jun 15 20:18:29.708873 2026] [security2:error] [pid 51003:tid 51180] [client 208.84.101.17:37458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "simmonsbankusa.com"] [uri "/.env.production.backup"] [unique_id "ajCydcpsKyvb75pkSvaVEQAAAb4"]
[Mon Jun 15 20:18:29.708993 2026] [security2:error] [pid 53359:tid 53535] [client 208.84.101.17:37464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "simmonsbankusa.com"] [uri "/.env.production.bak"] [unique_id "ajCydfC2Xs1VMQlhsgaynAAAAjw"]
[Mon Jun 15 20:18:29.710288 2026] [core:error] [pid 51003:tid 51232] [client 208.84.101.17:37528] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jun 15 20:18:29.710303 2026] [core:error] [pid 51003:tid 51232] [client 208.84.101.17:37528] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jun 15 20:18:29.793252 2026] [security2:error] [pid 53359:tid 53518] [client 208.84.101.17:37400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "simmonsbankusa.com"] [uri "/.env.local.bak"] [unique_id "ajCydfC2Xs1VMQlhsgaynwAAAis"]
[Mon Jun 15 20:18:29.793255 2026] [security2:error] [pid 51003:tid 51143] [client 208.84.101.17:37420] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "simmonsbankusa.com"] [uri "/.env.orig"] [unique_id "ajCydcpsKyvb75pkSvaVGAAAAZk"]
[Mon Jun 15 20:18:29.798012 2026] [core:error] [pid 53359:tid 53532] [client 208.84.101.17:37378] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jun 15 20:18:29.798031 2026] [core:error] [pid 53359:tid 53532] [client 208.84.101.17:37378] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jun 15 20:18:29.798552 2026] [security2:error] [pid 51003:tid 51219] [client 208.84.101.17:37414] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "simmonsbankusa.com"] [uri "/.env.local~"] [unique_id "ajCydcpsKyvb75pkSvaVGgAAAeU"]
[Mon Jun 15 20:18:29.798555 2026] [security2:error] [pid 51003:tid 51150] [client 208.84.101.17:37394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "simmonsbankusa.com"] [uri "/.env.local.orig"] [unique_id "ajCydcpsKyvb75pkSvaVGQAAAaA"]
[Mon Jun 15 20:18:29.798557 2026] [security2:error] [pid 53359:tid 53588] [client 208.84.101.17:37356] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "simmonsbankusa.com"] [uri "/.env.local.swp"] [unique_id "ajCydfC2Xs1VMQlhsgayoQAAAnE"]
[Mon Jun 15 20:18:29.799787 2026] [security2:error] [pid 51003:tid 51231] [client 208.84.101.17:37444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "simmonsbankusa.com"] [uri "/.env.local.copy"] [unique_id "ajCydcpsKyvb75pkSvaVGwAAAfE"]
[Mon Jun 15 20:18:29.825631 2026] [security2:error] [pid 51003:tid 51159] [client 103.125.146.75:27789] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/themes/twentytwentytwo/assets/fonts/"] [unique_id "ajCydcpsKyvb75pkSvaVHQAAAak"]
[Mon Jun 15 20:18:29.901701 2026] [security2:error] [pid 53359:tid 53568] [client 65.111.30.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.procrastinatingworker.imcorp.in"] [uri "/index.php"] [unique_id "ajCydfC2Xs1VMQlhsgayngAAAl0"]
[Mon Jun 15 20:18:29.915032 2026] [security2:error] [pid 51003:tid 51100] [remote 74.7.242.56:50374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.242.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.softhubtechno.ehx.czu.mybluehostin.me"] [uri "/images/img/Admin/logo/images/Admin/logo/js/Admin/logo/images/carrer.php"] [unique_id "ajCydcpsKyvb75pkSvaVHgAB-mA"], referer: https://www.softhubtechno.ehx.czu.mybluehostin.me/images/img/Admin/logo/images/Admin/logo/js/Admin/logo/images/Solutions-Banner.png
[Mon Jun 15 20:18:30.001940 2026] [security2:error] [pid 51003:tid 51197] [client 47.128.119.165:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCydcpsKyvb75pkSvaVCwABzzM"], referer: https://mywordsnthoughts.com/tag/turmeric-in-milk-for-babies/
[Mon Jun 15 20:18:30.059207 2026] [security2:error] [pid 53359:tid 53524] [client 47.128.119.165:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCydfC2Xs1VMQlhsgaykgACMTU"], referer: https://mywordsnthoughts.com/tag/turmeric-in-milk-for-babies/
[Mon Jun 15 20:18:30.180456 2026] [security2:error] [pid 51003:tid 51260] [client 43.173.182.18:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "itdeed.com"] [uri "/demomahayogini/product/love-astrology-services-marriage-report"] [unique_id "ajCydspsKyvb75pkSvaVJAAAAg4"]
[Mon Jun 15 20:18:30.191937 2026] [security2:error] [pid 53359:tid 53620] [client 103.125.146.70:57221] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/sodium_compat/wp-conflg.php"] [unique_id "ajCydvC2Xs1VMQlhsgaysAAAApE"]
[Mon Jun 15 20:18:30.231299 2026] [security2:error] [pid 53359:tid 53511] [client 66.249.68.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.balador.in"] [uri "/index.php"] [unique_id "ajCydfC2Xs1VMQlhsgayfAAAAiQ"]
[Mon Jun 15 20:18:30.234829 2026] [security2:error] [pid 51003:tid 51199] [client 66.249.68.2:38736] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.balador.in"] [uri "/index.php"] [unique_id "ajCydcpsKyvb75pkSvaU_AAAAdE"]
[Mon Jun 15 20:18:30.657908 2026] [security2:error] [pid 53359:tid 53535] [client 103.125.146.64:55171] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/sitemaps/"] [unique_id "ajCydvC2Xs1VMQlhsgayywAAAjw"]
[Mon Jun 15 20:18:30.999409 2026] [security2:error] [pid 51003:tid 51238] [client 57.141.14.73:44186] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCydspsKyvb75pkSvaVQQAB-Dw"]
[Mon Jun 15 20:18:31.033633 2026] [security2:error] [pid 53359:tid 53592] [client 103.125.146.34:21307] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/simple.php"] [unique_id "ajCyd_C2Xs1VMQlhsgay2AAAAnU"]
[Mon Jun 15 20:18:31.071019 2026] [security2:error] [pid 53359:tid 53580] [client 57.141.14.73:44176] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fifthestate.agency"] [uri "/index.php"] [unique_id "ajCydvC2Xs1VMQlhsgay0QACaXM"]
[Mon Jun 15 20:18:31.395271 2026] [security2:error] [pid 53359:tid 53533] [client 103.125.146.64:38269] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/uploads/wp-file-manager-pro/"] [unique_id "ajCyd_C2Xs1VMQlhsgay6wAAAjo"]
[Mon Jun 15 20:18:31.595368 2026] [security2:error] [pid 51003:tid 51093] [remote 185.68.18.52:11634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.18.68.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "chicceleb.com"] [uri "/wp-login.php"] [unique_id "ajCyd8psKyvb75pkSvaVUwABl1k"]
[Mon Jun 15 20:18:31.804896 2026] [security2:error] [pid 51003:tid 51189] [client 103.125.146.62:62203] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/sodium_compat/namespaced/Core/"] [unique_id "ajCyd8psKyvb75pkSvaVWAAAAcc"]
[Mon Jun 15 20:18:31.827883 2026] [security2:error] [pid 51003:tid 51095] [remote 216.73.217.151:1940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wilsonoverseas.com"] [uri "/"] [unique_id "ajCyd8psKyvb75pkSvaVWQABsVs"]
[Mon Jun 15 20:18:31.848039 2026] [security2:error] [pid 51003:tid 51029] [remote 111.225.149.195:46798] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sports-window.com"] [uri "/product/yonex-arcsaber-69-light-badminton-racquet"] [unique_id "ajCyd8psKyvb75pkSvaVWwACARk"]
[Mon Jun 15 20:18:31.944276 2026] [security2:error] [pid 53359:tid 53543] [client 57.141.14.13:61411] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyd_C2Xs1VMQlhsgay8QACRGY"]
[Mon Jun 15 20:18:31.970881 2026] [security2:error] [pid 51003:tid 51217] [client 74.7.227.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCyd8psKyvb75pkSvaVVQAB4ys"], referer: https://mywordsnthoughts.com/tag/reference-hub-general-topics/page/2/
[Mon Jun 15 20:18:31.991526 2026] [security2:error] [pid 51003:tid 51046] [remote 176.61.149.165:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.149.61.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seafaithst.com"] [uri "/wp-login.php"] [unique_id "ajCyd8psKyvb75pkSvaVYAABwio"]
[Mon Jun 15 20:18:32.228903 2026] [security2:error] [pid 53359:tid 53564] [client 103.125.146.34:59293] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-admin/css/colors/midnight/"] [unique_id "ajCyePC2Xs1VMQlhsgay-wAAAlk"]
[Mon Jun 15 20:18:32.229703 2026] [security2:error] [pid 51003:tid 51067] [remote 161.248.189.34:57294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.189.248.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nutreefarm.com"] [uri "/wp-login.php"] [unique_id "ajCyeMpsKyvb75pkSvaVZQAB4D8"]
[Mon Jun 15 20:18:32.328286 2026] [security2:error] [pid 51003:tid 51066] [remote 188.166.231.216:47486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.231.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lafitnessmembership.onl"] [uri "/wp-login.php"] [unique_id "ajCyeMpsKyvb75pkSvaVawACAz4"]
[Mon Jun 15 20:18:32.353583 2026] [security2:error] [pid 51003:tid 51183] [client 65.111.30.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.procrastinatingworker.imcorp.in"] [uri "/index.php"] [unique_id "ajCyeMpsKyvb75pkSvaVaQAAAcE"]
[Mon Jun 15 20:18:32.590964 2026] [security2:error] [pid 53359:tid 53465] [remote 176.61.149.165:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.149.61.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seafaithst.com"] [uri "/wp-login.php"] [unique_id "ajCyePC2Xs1VMQlhsgazDAACVmM"], referer: https://seafaithst.com/wp-login.php
[Mon Jun 15 20:18:32.622608 2026] [security2:error] [pid 53359:tid 53600] [client 103.125.146.61:31409] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-admin/admin.php"] [unique_id "ajCyePC2Xs1VMQlhsgazDgAAAn0"]
[Mon Jun 15 20:18:32.751635 2026] [security2:error] [pid 53359:tid 53620] [client 47.79.206.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "societytodaynews.com"] [uri "/index.php"] [unique_id "ajCyePC2Xs1VMQlhsgazBgAAApE"], referer: https://www.google.com/
[Mon Jun 15 20:18:32.885298 2026] [security2:error] [pid 53359:tid 53437] [remote 176.61.149.165:46564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.149.61.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ariakitsol.com"] [uri "/wp-login.php"] [unique_id "ajCyePC2Xs1VMQlhsgazHgACS0c"]
[Mon Jun 15 20:18:32.968156 2026] [security2:error] [pid 53359:tid 53523] [client 57.141.14.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "studioforge.in"] [uri "/index.php"] [unique_id "ajCyePC2Xs1VMQlhsgazFAAAAjA"]
[Mon Jun 15 20:18:32.990415 2026] [security2:error] [pid 51003:tid 51160] [client 103.125.146.62:32789] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/themes/twentytwentyfive/parts/"] [unique_id "ajCyeMpsKyvb75pkSvaVfAAAAao"]
[Mon Jun 15 20:18:33.055911 2026] [security2:error] [pid 51003:tid 51122] [remote 188.166.231.216:47486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.231.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lafitnessmembership.onl"] [uri "/wp-login.php"] [unique_id "ajCyecpsKyvb75pkSvaVfgAB8XY"], referer: https://lafitnessmembership.onl/wp-login.php
[Mon Jun 15 20:18:33.225490 2026] [security2:error] [pid 53359:tid 53382] [remote 176.61.149.165:46564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.149.61.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ariakitsol.com"] [uri "/wp-login.php"] [unique_id "ajCyefC2Xs1VMQlhsgazKAACNRA"], referer: https://ariakitsol.com/wp-login.php
[Mon Jun 15 20:18:33.261057 2026] [security2:error] [pid 53359:tid 53593] [client 160.19.16.45:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "itdeed.com"] [uri "/demomahayogini/product/love-astrology-services-marriage-report"] [unique_id "ajCyefC2Xs1VMQlhsgazKwAAAnY"]
[Mon Jun 15 20:18:33.363708 2026] [security2:error] [pid 51003:tid 51101] [remote 128.199.17.23:56282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.17.199.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myexcelguide.com"] [uri "/wp-login.php"] [unique_id "ajCyecpsKyvb75pkSvaVhgAB_2E"]
[Mon Jun 15 20:18:33.373283 2026] [security2:error] [pid 53359:tid 53522] [client 181.10.76.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kthemani.com"] [uri "/index.php"] [unique_id "ajCyd_C2Xs1VMQlhsgay5QAAAi8"]
[Mon Jun 15 20:18:33.403596 2026] [security2:error] [pid 51003:tid 51187] [client 103.125.146.30:40021] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/themes/about.php"] [unique_id "ajCyecpsKyvb75pkSvaVhwAAAcU"]
[Mon Jun 15 20:18:33.778433 2026] [security2:error] [pid 51003:tid 51080] [remote 128.199.17.23:56282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.17.199.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myexcelguide.com"] [uri "/wp-login.php"] [unique_id "ajCyecpsKyvb75pkSvaVjAAB7Uw"], referer: https://myexcelguide.com/wp-login.php
[Mon Jun 15 20:18:33.785221 2026] [security2:error] [pid 53359:tid 53600] [client 57.141.14.27:43250] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyefC2Xs1VMQlhsgazNwACfRc"]
[Mon Jun 15 20:18:33.822716 2026] [security2:error] [pid 53359:tid 53614] [client 3.226.51.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "binnyseasyrecipes.com"] [uri "/index.php"] [unique_id "ajCyefC2Xs1VMQlhsgazNgAAAos"]
[Mon Jun 15 20:18:33.825671 2026] [security2:error] [pid 53359:tid 53497] [client 103.125.146.68:39729] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-admin/css/colors/ectoplasm/"] [unique_id "ajCyefC2Xs1VMQlhsgazRQAAAhY"]
[Mon Jun 15 20:18:34.046760 2026] [security2:error] [pid 51003:tid 51062] [remote 161.248.189.34:57294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.189.248.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nutreefarm.com"] [uri "/wp-login.php"] [unique_id "ajCyespsKyvb75pkSvaVlwABsTo"], referer: https://nutreefarm.com/wp-login.php
[Mon Jun 15 20:18:34.221934 2026] [security2:error] [pid 53359:tid 53502] [client 103.125.146.39:45631] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/xxx.php"] [unique_id "ajCyevC2Xs1VMQlhsgazVgAAAhs"]
[Mon Jun 15 20:18:34.403975 2026] [security2:error] [pid 51003:tid 51044] [remote 57.141.14.54:54469] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fifthestate.agency"] [uri "/index.php"] [unique_id "ajCyespsKyvb75pkSvaVnAACBSg"]
[Mon Jun 15 20:18:34.593927 2026] [security2:error] [pid 53359:tid 53588] [client 103.125.146.60:33225] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-admin/about.php"] [unique_id "ajCyevC2Xs1VMQlhsgazXQAAAnE"]
[Mon Jun 15 20:18:34.935788 2026] [security2:error] [pid 51003:tid 51036] [remote 115.78.9.138:49754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.9.78.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bharathanceramics.com"] [uri "/wp-login.php"] [unique_id "ajCyespsKyvb75pkSvaVrgAB6CA"]
[Mon Jun 15 20:18:34.990067 2026] [security2:error] [pid 53359:tid 53505] [client 103.125.146.55:49471] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/pomo/"] [unique_id "ajCyevC2Xs1VMQlhsgazYQAAAh4"]
[Mon Jun 15 20:18:35.206044 2026] [autoindex:error] [pid 51003:tid 51191] [client 208.84.101.17:37498] AH01276: Cannot serve directory /home1/rugqjjmy/public_html/simmonsbankusa/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:18:35.384836 2026] [security2:error] [pid 51003:tid 51006] [remote 121.200.216.55:48116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilsonoverseas.com"] [uri "/wp-login.php"] [unique_id "ajCye8psKyvb75pkSvaVuAAB5AI"]
[Mon Jun 15 20:18:35.443215 2026] [security2:error] [pid 51003:tid 51199] [client 103.125.146.41:49749] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/themes/twentytwentytwo/assets/about.php"] [unique_id "ajCye8psKyvb75pkSvaVvAAAAdE"]
[Mon Jun 15 20:18:35.506883 2026] [security2:error] [pid 51003:tid 51154] [client 31.219.209.201:52425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.209.219.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCye8psKyvb75pkSvaVxQAAAaQ"]
[Mon Jun 15 20:18:35.512352 2026] [security2:error] [pid 51003:tid 51154] [client 31.219.209.201:52425] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCye8psKyvb75pkSvaVxQAAAaQ"]
[Mon Jun 15 20:18:35.599299 2026] [security2:error] [pid 53359:tid 53472] [remote 57.141.14.108:58337] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCye_C2Xs1VMQlhsgazhwACW2o"]
[Mon Jun 15 20:18:35.880199 2026] [security2:error] [pid 51003:tid 51248] [client 103.125.146.53:59835] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-admin/images/user/"] [unique_id "ajCye8psKyvb75pkSvaV3gAAAgI"]
[Mon Jun 15 20:18:35.891056 2026] [security2:error] [pid 51003:tid 51075] [remote 121.200.216.55:48116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilsonoverseas.com"] [uri "/wp-login.php"] [unique_id "ajCye8psKyvb75pkSvaV3QAB10c"], referer: https://wilsonoverseas.com/wp-login.php
[Mon Jun 15 20:18:35.956464 2026] [security2:error] [pid 53359:tid 53577] [client 121.229.156.56:50632] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.diggysguide.com"] [uri "/awesome-alchemy/deciduous-forest"] [unique_id "ajCye_C2Xs1VMQlhsgazqgAAAmY"]
[Mon Jun 15 20:18:35.956596 2026] [security2:error] [pid 53359:tid 53577] [client 121.229.156.56:50632] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.diggysguide.com"] [uri "/awesome-alchemy/deciduous-forest"] [unique_id "ajCye_C2Xs1VMQlhsgazqgAAAmY"]
[Mon Jun 15 20:18:36.000920 2026] [security2:error] [pid 53359:tid 53562] [client 57.141.14.67:57947] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCye_C2Xs1VMQlhsgazqAACVxY"]
[Mon Jun 15 20:18:36.173043 2026] [security2:error] [pid 51003:tid 51127] [remote 78.46.92.235:48264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.92.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sriramsewatrust.com"] [uri "/wp-login.php"] [unique_id "ajCyfMpsKyvb75pkSvaV5wABxXs"]
[Mon Jun 15 20:18:36.294203 2026] [security2:error] [pid 51003:tid 51247] [client 103.125.146.62:35799] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/mah/function.php"] [unique_id "ajCyfMpsKyvb75pkSvaV6gAAAgE"]
[Mon Jun 15 20:18:36.376344 2026] [security2:error] [pid 51003:tid 51131] [remote 78.46.92.235:48264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.92.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sriramsewatrust.com"] [uri "/wp-login.php"] [unique_id "ajCyfMpsKyvb75pkSvaV7QAB0X8"], referer: https://sriramsewatrust.com/wp-login.php
[Mon Jun 15 20:18:36.481974 2026] [security2:error] [pid 51003:tid 51249] [client 95.26.42.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kthemani.com"] [uri "/index.php"] [unique_id "ajCyespsKyvb75pkSvaVqQACA20"]
[Mon Jun 15 20:18:36.722608 2026] [security2:error] [pid 51003:tid 51220] [client 103.125.146.56:57033] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/blocks/footnotes/"] [unique_id "ajCyfMpsKyvb75pkSvaV9gAAAeY"]
[Mon Jun 15 20:18:36.796672 2026] [security2:error] [pid 53359:tid 53590] [client 143.244.57.120:40826] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "www.surveylaya.com"] [uri "/wp-admin/index.php"] [unique_id "ajCyfPC2Xs1VMQlhsgaztAAAAnM"]
[Mon Jun 15 20:18:36.994512 2026] [security2:error] [pid 53359:tid 53543] [client 143.244.57.120:40826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.surveylaya.com"] [uri "/wp-login.php"] [unique_id "ajCyfPC2Xs1VMQlhsgazwAAAAkQ"]
[Mon Jun 15 20:18:36.994638 2026] [security2:error] [pid 53359:tid 53543] [client 143.244.57.120:40826] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.surveylaya.com"] [uri "/wp-login.php"] [unique_id "ajCyfPC2Xs1VMQlhsgazwAAAAkQ"]
[Mon Jun 15 20:18:37.133468 2026] [security2:error] [pid 51003:tid 51135] [client 103.125.146.32:56745] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/sodium_compat/src/Core/"] [unique_id "ajCyfcpsKyvb75pkSvaWBAAAAZE"]
[Mon Jun 15 20:18:37.391232 2026] [security2:error] [pid 53359:tid 53609] [client 57.141.14.73:44258] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fifthestate.agency"] [uri "/index.php"] [unique_id "ajCyffC2Xs1VMQlhsgazwgAChgg"]
[Mon Jun 15 20:18:37.393083 2026] [security2:error] [pid 51003:tid 51242] [client 57.141.14.11:30141] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyfcpsKyvb75pkSvaWBgAB_Cw"]
[Mon Jun 15 20:18:37.545440 2026] [security2:error] [pid 53359:tid 53598] [client 103.125.146.79:26911] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-admin/backup.php"] [unique_id "ajCyffC2Xs1VMQlhsgazyQAAAns"]
[Mon Jun 15 20:18:37.609014 2026] [security2:error] [pid 53359:tid 53375] [remote 47.128.32.69:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mywordsnthoughts.com"] [uri "/10-hair-colouring-tips-for-you/"] [unique_id "ajCyffC2Xs1VMQlhsgazywACQgk"]
[Mon Jun 15 20:18:37.739546 2026] [security2:error] [pid 53359:tid 53574] [client 104.207.55.47:61233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.55.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rajunandkardeputycollector.blog"] [uri "/wp-login.php"] [unique_id "ajCyffC2Xs1VMQlhsgazzAAAAmM"], referer: https://rajunandkardeputycollector.blog/wp-login.php
[Mon Jun 15 20:18:38.024448 2026] [security2:error] [pid 53359:tid 53509] [client 103.125.146.78:64513] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/panel.php"] [unique_id "ajCyfvC2Xs1VMQlhsgaz1AAAAiI"]
[Mon Jun 15 20:18:38.052104 2026] [rewrite:error] [pid 53359:tid 53606] [client 47.79.198.151:9120] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:18:38.406759 2026] [security2:error] [pid 51003:tid 51204] [client 103.125.146.55:50067] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-admin/css/colors/ocean/"] [unique_id "ajCyfspsKyvb75pkSvaWGgAAAdY"]
[Mon Jun 15 20:18:38.435401 2026] [security2:error] [pid 51003:tid 51182] [client 184.72.197.152:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "binnyseasyrecipes.com"] [uri "/index.php"] [unique_id "ajCyfspsKyvb75pkSvaWGAAAAcA"]
[Mon Jun 15 20:18:38.496712 2026] [rewrite:error] [pid 53359:tid 53621] [client 47.79.198.151:9120] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:18:38.792560 2026] [security2:error] [pid 53359:tid 53507] [client 57.141.14.92:32278] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyfvC2Xs1VMQlhsgaz-gACIHQ"]
[Mon Jun 15 20:18:38.842249 2026] [security2:error] [pid 51003:tid 51142] [client 103.125.146.76:59221] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/Requests/src/Proxy/"] [unique_id "ajCyfspsKyvb75pkSvaWIwAAAZg"]
[Mon Jun 15 20:18:39.023478 2026] [security2:error] [pid 53359:tid 53620] [client 185.2.235.244:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pehelfoundation.org"] [uri "/index.php"] [unique_id "ajCyffC2Xs1VMQlhsgaz0wAAApE"]
[Mon Jun 15 20:18:39.032040 2026] [security2:error] [pid 51003:tid 51218] [client 126.209.47.75:58725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.47.209.126.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nxtal.com"] [uri "/xmlrpc.php"] [unique_id "ajCyf8psKyvb75pkSvaWKgAAAeQ"]
[Mon Jun 15 20:18:39.032137 2026] [security2:error] [pid 51003:tid 51218] [client 126.209.47.75:58725] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nxtal.com"] [uri "/xmlrpc.php"] [unique_id "ajCyf8psKyvb75pkSvaWKgAAAeQ"]
[Mon Jun 15 20:18:39.205302 2026] [security2:error] [pid 51003:tid 51095] [remote 176.61.149.165:46566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.149.61.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohandasgupta.com"] [uri "/wp-login.php"] [unique_id "ajCyf8psKyvb75pkSvaWMQACA1s"]
[Mon Jun 15 20:18:39.257629 2026] [security2:error] [pid 51003:tid 51202] [client 103.125.146.39:24995] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-good.php"] [unique_id "ajCyf8psKyvb75pkSvaWMgAAAdQ"]
[Mon Jun 15 20:18:39.343707 2026] [security2:error] [pid 53359:tid 53384] [remote 47.128.62.23:35910] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "astonetech.com"] [uri "/men/tops-men/hoodies-and-sweatshirts-men.html"] [unique_id "ajCyf_C2Xs1VMQlhsga0CAACKhI"]
[Mon Jun 15 20:18:39.366733 2026] [rewrite:error] [pid 53359:tid 53381] [remote 47.79.197.171:23426] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:18:39.450910 2026] [security2:error] [pid 51003:tid 51029] [remote 176.61.149.165:46566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.149.61.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohandasgupta.com"] [uri "/wp-login.php"] [unique_id "ajCyf8psKyvb75pkSvaWNgABxxk"], referer: https://rohandasgupta.com/wp-login.php
[Mon Jun 15 20:18:39.632661 2026] [rewrite:error] [pid 53359:tid 53443] [remote 47.79.197.171:23426] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:18:39.690458 2026] [security2:error] [pid 53359:tid 53621] [client 103.125.146.56:24029] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/fonts/wp-conflg.php"] [unique_id "ajCyf_C2Xs1VMQlhsga0EAAAApI"]
[Mon Jun 15 20:18:40.119208 2026] [security2:error] [pid 53359:tid 53502] [client 103.125.146.66:53263] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-admin/install-helper-new.php"] [unique_id "ajCygPC2Xs1VMQlhsga0GwAAAhs"]
[Mon Jun 15 20:18:40.170806 2026] [security2:error] [pid 51003:tid 51153] [client 192.140.64.94:29964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.64.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCygMpsKyvb75pkSvaWRAAAAaM"]
[Mon Jun 15 20:18:40.170930 2026] [security2:error] [pid 51003:tid 51153] [client 192.140.64.94:29964] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCygMpsKyvb75pkSvaWRAAAAaM"]
[Mon Jun 15 20:18:40.468917 2026] [security2:error] [pid 53359:tid 53599] [client 95.27.48.215:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kthemani.com"] [uri "/index.php"] [unique_id "ajCyfvC2Xs1VMQlhsgaz8AAAAnw"]
[Mon Jun 15 20:18:40.509569 2026] [security2:error] [pid 53359:tid 53507] [client 57.141.14.7:42429] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCygPC2Xs1VMQlhsga0IwACIF0"]
[Mon Jun 15 20:18:40.512898 2026] [security2:error] [pid 53359:tid 53534] [client 103.125.146.35:48223] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/admin/"] [unique_id "ajCygPC2Xs1VMQlhsga0KgAAAjs"]
[Mon Jun 15 20:18:40.587304 2026] [security2:error] [pid 51003:tid 51053] [remote 144.76.80.54:55306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.80.76.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.qjn.jfj.mybluehostin.me"] [uri "/wp-login.php"] [unique_id "ajCygMpsKyvb75pkSvaWTQABvjE"]
[Mon Jun 15 20:18:40.594135 2026] [security2:error] [pid 51003:tid 51207] [client 162.214.80.21:20306] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "talkmint.com"] [uri "/wp-content/uploads/2023/11/logo.png.webp"] [unique_id "ajCygMpsKyvb75pkSvaWTgAAAdk"]
[Mon Jun 15 20:18:40.613515 2026] [security2:error] [pid 51003:tid 51197] [client 162.214.80.21:20320] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "talkmint.com"] [uri "/wp-content/uploads/2023/11/footer-logo.png.webp"] [unique_id "ajCygMpsKyvb75pkSvaWTwAAAc8"]
[Mon Jun 15 20:18:40.625547 2026] [security2:error] [pid 53359:tid 53615] [client 52.167.144.203:34282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talkmint.com"] [uri "/index.php"] [unique_id "ajCygPC2Xs1VMQlhsga0JgACjBE"]
[Mon Jun 15 20:18:40.933213 2026] [security2:error] [pid 53359:tid 53503] [client 103.125.146.41:27543] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/js/tinymce/skins/lightgray/img/"] [unique_id "ajCygPC2Xs1VMQlhsga0MQAAAhw"]
[Mon Jun 15 20:18:40.972140 2026] [security2:error] [pid 53359:tid 53376] [remote 5.255.231.42:0] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.smgl.org"] [uri "/robots.txt"] [unique_id "ajCygPC2Xs1VMQlhsga0NAACIgo"]
[Mon Jun 15 20:18:41.000200 2026] [security2:error] [pid 51003:tid 51256] [client 57.141.14.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aarohiarts.org"] [uri "/index.php"] [unique_id "ajCygMpsKyvb75pkSvaWVAAAAgo"]
[Mon Jun 15 20:18:41.025087 2026] [security2:error] [pid 51003:tid 51243] [client 18.207.177.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCygMpsKyvb75pkSvaWVgAB_RI"]
[Mon Jun 15 20:18:41.183101 2026] [security2:error] [pid 51003:tid 51083] [remote 121.200.216.55:48142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jaipurtissues.com"] [uri "/wp-login.php"] [unique_id "ajCygcpsKyvb75pkSvaWWQAB2E8"]
[Mon Jun 15 20:18:41.469553 2026] [rewrite:error] [pid 51003:tid 51117] [remote 47.79.199.21:32682] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:18:41.535352 2026] [security2:error] [pid 51003:tid 51144] [client 103.125.146.80:59655] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/rest-api/endpoints/"] [unique_id "ajCygcpsKyvb75pkSvaWZAAAAZo"]
[Mon Jun 15 20:18:41.647370 2026] [security2:error] [pid 51003:tid 51065] [remote 121.200.216.55:48142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jaipurtissues.com"] [uri "/wp-login.php"] [unique_id "ajCygcpsKyvb75pkSvaWZwABrD0"], referer: https://jaipurtissues.com/wp-login.php
[Mon Jun 15 20:18:41.728636 2026] [rewrite:error] [pid 51003:tid 51111] [remote 47.79.199.21:32682] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:18:41.827992 2026] [security2:error] [pid 53359:tid 53468] [remote 57.141.14.42:65042] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCygfC2Xs1VMQlhsga0RAACi2Y"]
[Mon Jun 15 20:18:41.860453 2026] [security2:error] [pid 51003:tid 51123] [remote 91.146.99.41:38928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.99.146.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "argosgems.annamjewels.com"] [uri "/wp-login.php"] [unique_id "ajCygcpsKyvb75pkSvaWbgAB3Xc"]
[Mon Jun 15 20:18:41.913069 2026] [security2:error] [pid 53359:tid 53553] [client 103.125.146.75:47241] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/login.php"] [unique_id "ajCygfC2Xs1VMQlhsga0SgAAAk4"]
[Mon Jun 15 20:18:41.992842 2026] [security2:error] [pid 51003:tid 51202] [client 162.43.236.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCygcpsKyvb75pkSvaWbAAB1G8"]
[Mon Jun 15 20:18:42.101022 2026] [security2:error] [pid 51003:tid 51019] [remote 91.146.99.41:38928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.99.146.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "argosgems.annamjewels.com"] [uri "/wp-login.php"] [unique_id "ajCygspsKyvb75pkSvaWdwAB0w8"], referer: https://argosgems.annamjewels.com/wp-login.php
[Mon Jun 15 20:18:42.424475 2026] [security2:error] [pid 53359:tid 53456] [remote 216.73.217.151:44950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wilsonoverseas.com"] [uri "/"] [unique_id "ajCygvC2Xs1VMQlhsga0VgACXVo"]
[Mon Jun 15 20:18:42.543263 2026] [security2:error] [pid 53359:tid 53619] [client 103.125.146.68:22817] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/blocks/button/"] [unique_id "ajCygvC2Xs1VMQlhsga0VwAAApA"]
[Mon Jun 15 20:18:42.810050 2026] [security2:error] [pid 53359:tid 53466] [remote 64.131.86.2:42084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.86.131.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "readerwiz.com"] [uri "/wp-login.php"] [unique_id "ajCygvC2Xs1VMQlhsga0XAACUmQ"]
[Mon Jun 15 20:18:43.015411 2026] [security2:error] [pid 53359:tid 53430] [remote 64.131.86.2:42084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.86.131.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "readerwiz.com"] [uri "/wp-login.php"] [unique_id "ajCyg_C2Xs1VMQlhsga0ZQACPUA"], referer: https://readerwiz.com/wp-login.php
[Mon Jun 15 20:18:43.019609 2026] [security2:error] [pid 51003:tid 51036] [remote 144.76.80.54:55306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.80.76.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.qjn.jfj.mybluehostin.me"] [uri "/wp-login.php"] [unique_id "ajCyg8psKyvb75pkSvaWigAB1iA"], referer: https://mail.qjn.jfj.mybluehostin.me/wp-login.php
[Mon Jun 15 20:18:43.106503 2026] [security2:error] [pid 53359:tid 53583] [client 103.125.146.71:33863] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/block-supports/222.php"] [unique_id "ajCyg_C2Xs1VMQlhsga0ZgAAAmw"]
[Mon Jun 15 20:18:43.279424 2026] [security2:error] [pid 53359:tid 53608] [client 78.114.12.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kthemani.com"] [uri "/index.php"] [unique_id "ajCygfC2Xs1VMQlhsga0QQAChSM"]
[Mon Jun 15 20:18:43.518533 2026] [security2:error] [pid 51003:tid 51198] [client 103.125.146.70:26209] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/Requests/src/Utility/"] [unique_id "ajCyg8psKyvb75pkSvaWlwAAAdA"]
[Mon Jun 15 20:18:43.577299 2026] [rewrite:error] [pid 51003:tid 51010] [remote 47.79.199.86:37654] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:18:43.732842 2026] [security2:error] [pid 53359:tid 53555] [client 103.20.126.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.travelmax.in"] [uri "/index.php"] [unique_id "ajCyg_C2Xs1VMQlhsga0bgACUH8"]
[Mon Jun 15 20:18:43.750771 2026] [security2:error] [pid 53359:tid 53560] [client 57.141.14.28:57396] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyg_C2Xs1VMQlhsga0cgACVU4"]
[Mon Jun 15 20:18:43.839224 2026] [rewrite:error] [pid 51003:tid 51018] [remote 47.79.199.86:37654] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:18:43.909093 2026] [security2:error] [pid 53359:tid 53506] [client 103.125.146.75:47935] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/PHPMailer/widgets/"] [unique_id "ajCyg_C2Xs1VMQlhsga0eAAAAh8"]
[Mon Jun 15 20:18:43.910259 2026] [security2:error] [pid 51003:tid 51075] [remote 103.127.30.137:50050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.30.127.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "euroshopfronts.co.uk"] [uri "/wp-login.php"] [unique_id "ajCyg8psKyvb75pkSvaWpAAB5Ec"]
[Mon Jun 15 20:18:44.327261 2026] [security2:error] [pid 51003:tid 51195] [client 103.125.146.54:52415] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/blocks/query-title/"] [unique_id "ajCyhMpsKyvb75pkSvaWqAAAAc0"]
[Mon Jun 15 20:18:44.391098 2026] [security2:error] [pid 51003:tid 51043] [remote 103.127.30.137:50050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.30.127.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "euroshopfronts.co.uk"] [uri "/wp-login.php"] [unique_id "ajCyhMpsKyvb75pkSvaWrAABzCc"], referer: https://euroshopfronts.co.uk/wp-login.php
[Mon Jun 15 20:18:44.495795 2026] [security2:error] [pid 53359:tid 53576] [client 143.244.57.88:54032] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "rkfreshmart.net"] [uri "/wp-content/themes/"] [unique_id "ajCyhPC2Xs1VMQlhsga0hAAAAmU"]
[Mon Jun 15 20:18:44.602214 2026] [security2:error] [pid 53359:tid 53551] [client 65.111.30.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.procrastinatingworker.imcorp.in"] [uri "/index.php"] [unique_id "ajCyhPC2Xs1VMQlhsga0gwAAAkw"]
[Mon Jun 15 20:18:44.645943 2026] [security2:error] [pid 51003:tid 51258] [client 49.37.157.202:58234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "desidelightmp.com"] [uri "/xmlrpc.php"] [unique_id "ajCyhMpsKyvb75pkSvaWuQAAAgw"]
[Mon Jun 15 20:18:44.646078 2026] [security2:error] [pid 51003:tid 51258] [client 49.37.157.202:58234] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "desidelightmp.com"] [uri "/xmlrpc.php"] [unique_id "ajCyhMpsKyvb75pkSvaWuQAAAgw"]
[Mon Jun 15 20:18:44.653531 2026] [security2:error] [pid 53359:tid 53480] [remote 74.7.243.230:38150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shreeramsweets-co-in.xgh.ggk.mybluehostin.me"] [uri "/plugins/owl-carousel/js/css/plugins/lightgallery/js/images_scroller/plugins/lightgallery/js/rangeslider/images/images_scroller/hampers-gift.php"] [unique_id "ajCyhPC2Xs1VMQlhsga0iAACgnI"], referer: https://shreeramsweets-co-in.xgh.ggk.mybluehostin.me/plugins/owl-carousel/js/css/plugins/lightgallery/js/images_scroller/plugins/lightgallery/js/rangeslider/images/images_scroller/banner2.jpg
[Mon Jun 15 20:18:44.753544 2026] [security2:error] [pid 53359:tid 53595] [client 103.125.146.57:49605] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/ID3/module.tag.lyrics3-class.php"] [unique_id "ajCyhPC2Xs1VMQlhsga0igAAAng"]
[Mon Jun 15 20:18:44.962981 2026] [security2:error] [pid 51003:tid 51109] [remote 57.141.14.68:59990] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyhMpsKyvb75pkSvaWwQABzmk"]
[Mon Jun 15 20:18:45.198632 2026] [security2:error] [pid 51003:tid 51247] [client 103.125.146.73:25771] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-admin/css/colors/sunrise/"] [unique_id "ajCyhcpsKyvb75pkSvaWzwAAAgE"]
[Mon Jun 15 20:18:45.321523 2026] [security2:error] [pid 51003:tid 51193] [client 47.79.207.103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "societytodaynews.com"] [uri "/index.php"] [unique_id "ajCyhcpsKyvb75pkSvaWzAAAAcs"], referer: https://www.google.com/
[Mon Jun 15 20:18:45.593671 2026] [security2:error] [pid 51003:tid 51146] [client 103.125.146.44:20079] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/themes/twentytwentyfour/patterns/template-singl-portfolio.php"] [unique_id "ajCyhcpsKyvb75pkSvaW2QAAAZw"]
[Mon Jun 15 20:18:45.692462 2026] [security2:error] [pid 53359:tid 53549] [client 149.88.23.79:57836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.23.88.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mizukicnc.com"] [uri "/xmlrpc.php"] [unique_id "ajCyhfC2Xs1VMQlhsga0mwAAAko"]
[Mon Jun 15 20:18:45.692608 2026] [security2:error] [pid 53359:tid 53549] [client 149.88.23.79:57836] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mizukicnc.com"] [uri "/xmlrpc.php"] [unique_id "ajCyhfC2Xs1VMQlhsga0mwAAAko"]
[Mon Jun 15 20:18:45.929177 2026] [security2:error] [pid 53359:tid 53390] [remote 176.61.149.165:41324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.149.61.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.jenordesignsllc.info"] [uri "/wp-login.php"] [unique_id "ajCyhfC2Xs1VMQlhsga0nQACUhg"]
[Mon Jun 15 20:18:46.003315 2026] [security2:error] [pid 51003:tid 51217] [client 103.125.146.31:42817] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/blocks/query-pagination-previous/"] [unique_id "ajCyhspsKyvb75pkSvaW4gAAAeM"]
[Mon Jun 15 20:18:46.026886 2026] [security2:error] [pid 53359:tid 53524] [client 103.20.126.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.travelmax.in"] [uri "/index.php"] [unique_id "ajCyhfC2Xs1VMQlhsga0ngACMVY"]
[Mon Jun 15 20:18:46.042857 2026] [security2:error] [pid 53359:tid 53606] [client 31.219.209.201:53033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.209.219.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCyhvC2Xs1VMQlhsga0oQAAAoM"]
[Mon Jun 15 20:18:46.051813 2026] [security2:error] [pid 53359:tid 53606] [client 31.219.209.201:53033] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCyhvC2Xs1VMQlhsga0oQAAAoM"]
[Mon Jun 15 20:18:46.413836 2026] [security2:error] [pid 51003:tid 51226] [client 103.125.146.31:28103] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/wp-config-backup.php"] [unique_id "ajCyhspsKyvb75pkSvaXBAAAAew"]
[Mon Jun 15 20:18:46.429865 2026] [security2:error] [pid 51003:tid 51170] [client 57.141.14.69:33466] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyhspsKyvb75pkSvaW8gABtDw"]
[Mon Jun 15 20:18:46.663462 2026] [security2:error] [pid 51003:tid 51183] [client 57.141.14.112:51672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "majividyarthikes.com"] [uri "/index.php"] [unique_id "ajCyhspsKyvb75pkSvaXBQABwTQ"]
[Mon Jun 15 20:18:46.804509 2026] [security2:error] [pid 53359:tid 53551] [client 103.125.146.77:64555] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/uploads/wp.php"] [unique_id "ajCyhvC2Xs1VMQlhsga0tQAAAkw"]
[Mon Jun 15 20:18:47.027070 2026] [security2:error] [pid 51003:tid 51157] [client 65.111.30.222:39517] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.procrastinatingworker.imcorp.in"] [uri "/index.php"] [unique_id "ajCyhspsKyvb75pkSvaXEAAAAac"]
[Mon Jun 15 20:18:47.057241 2026] [security2:error] [pid 53359:tid 53607] [client 139.99.122.191:53426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "xmlrpc\\\\.php" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "73"] [id "392331"] [rev "3"] [msg "Atomicorp.com WAF Rules: xmlrpc DOS attack"] [severity "CRITICAL"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCyh_C2Xs1VMQlhsga0uAAAAoQ"]
[Mon Jun 15 20:18:47.057355 2026] [security2:error] [pid 53359:tid 53607] [client 139.99.122.191:53426] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCyh_C2Xs1VMQlhsga0uAAAAoQ"]
[Mon Jun 15 20:18:47.099651 2026] [security2:error] [pid 53359:tid 53595] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "extrovertevents.com"] [uri "/wp-admin/install.php"] [unique_id "ajCyh_C2Xs1VMQlhsga0ugAAAng"]
[Mon Jun 15 20:18:47.109003 2026] [security2:error] [pid 53359:tid 53612] [client 91.171.212.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kthemani.com"] [uri "/index.php"] [unique_id "ajCyhfC2Xs1VMQlhsga0kQAAAok"]
[Mon Jun 15 20:18:47.196643 2026] [security2:error] [pid 51003:tid 51255] [client 103.125.146.76:58215] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/themes/news-portal/user-install.php"] [unique_id "ajCyh8psKyvb75pkSvaXGgAAAgk"]
[Mon Jun 15 20:18:47.303791 2026] [security2:error] [pid 51003:tid 51045] [remote 178.236.185.252:36714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.185.236.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spacerman.com"] [uri "/wp-login.php"] [unique_id "ajCyh8psKyvb75pkSvaXGwACASk"]
[Mon Jun 15 20:18:47.351316 2026] [security2:error] [pid 51003:tid 51188] [client 45.3.35.66:20545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.35.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rajunandkardeputycollector.blog"] [uri "/wp-login.php"] [unique_id "ajCyh8psKyvb75pkSvaXHQAAAcY"], referer: https://rajunandkardeputycollector.blog/wp-login.php
[Mon Jun 15 20:18:47.497782 2026] [security2:error] [pid 53359:tid 53441] [remote 91.146.99.41:41458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.99.146.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sonallirastogi.mqh.oxl.mybluehostin.me"] [uri "/wp-login.php"] [unique_id "ajCyh_C2Xs1VMQlhsga0xAACQEs"]
[Mon Jun 15 20:18:47.593001 2026] [security2:error] [pid 51003:tid 51210] [client 103.125.146.58:34141] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/themes/theme/about.php"] [unique_id "ajCyh8psKyvb75pkSvaXKgAAAdw"]
[Mon Jun 15 20:18:47.686841 2026] [security2:error] [pid 53359:tid 53427] [remote 176.61.149.165:41324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.149.61.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.jenordesignsllc.info"] [uri "/wp-login.php"] [unique_id "ajCyh_C2Xs1VMQlhsga0yAACaz0"], referer: https://mail.jenordesignsllc.info/wp-login.php
[Mon Jun 15 20:18:47.714886 2026] [security2:error] [pid 51003:tid 51111] [remote 178.236.185.252:36714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.185.236.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spacerman.com"] [uri "/wp-login.php"] [unique_id "ajCyh8psKyvb75pkSvaXLgABtGs"], referer: https://spacerman.com/wp-login.php
[Mon Jun 15 20:18:47.736932 2026] [security2:error] [pid 53359:tid 53368] [remote 91.146.99.41:41458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.99.146.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sonallirastogi.mqh.oxl.mybluehostin.me"] [uri "/wp-login.php"] [unique_id "ajCyh_C2Xs1VMQlhsga0yQACfwI"], referer: https://sonallirastogi.mqh.oxl.mybluehostin.me/wp-login.php
[Mon Jun 15 20:18:48.003814 2026] [security2:error] [pid 53359:tid 53557] [client 103.125.146.70:22493] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/js/tinymce/"] [unique_id "ajCyiPC2Xs1VMQlhsga00gAAAlI"]
[Mon Jun 15 20:18:48.015584 2026] [security2:error] [pid 53359:tid 53503] [client 57.141.14.30:43096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyh_C2Xs1VMQlhsga0ywACHBY"]
[Mon Jun 15 20:18:48.392933 2026] [security2:error] [pid 53359:tid 53497] [client 47.79.201.247:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "societytodaynews.com"] [uri "/index.php"] [unique_id "ajCyiPC2Xs1VMQlhsga01AAAAhY"], referer: https://www.google.com/
[Mon Jun 15 20:18:48.426214 2026] [security2:error] [pid 51003:tid 51254] [client 103.125.146.38:36085] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/themes/twentytwentyfour/assets/"] [unique_id "ajCyiMpsKyvb75pkSvaXSgAAAgg"]
[Mon Jun 15 20:18:48.576835 2026] [security2:error] [pid 53359:tid 53550] [client 157.245.231.21:60718] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "indusfinance.in"] [uri "/wp-login.php"] [unique_id "ajCyiPC2Xs1VMQlhsga03AAAAks"]
[Mon Jun 15 20:18:48.587517 2026] [security2:error] [pid 51003:tid 51247] [client 66.249.79.171:63798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.gpgaya.org"] [uri "/index.php"] [unique_id "ajCyiMpsKyvb75pkSvaXVAAAAgE"]
[Mon Jun 15 20:18:48.630946 2026] [security2:error] [pid 53359:tid 53566] [client 43.153.49.151:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "rudrakshwelfare.com"] [uri "/"] [unique_id "ajCyiPC2Xs1VMQlhsga04wAAAls"], referer: http://rudrakshwelfare.com
[Mon Jun 15 20:18:48.633162 2026] [security2:error] [pid 53359:tid 53498] [client 57.141.14.73:60780] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyiPC2Xs1VMQlhsga03gACF2I"]
[Mon Jun 15 20:18:48.665136 2026] [security2:error] [pid 53359:tid 53594] [client 57.141.14.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kthemani.com"] [uri "/index.php"] [unique_id "ajCyhvC2Xs1VMQlhsga0sgAAAnc"]
[Mon Jun 15 20:18:48.695687 2026] [security2:error] [pid 53359:tid 53564] [client 157.245.231.21:60737] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "indusfinance.in"] [uri "/wp-login.php"] [unique_id "ajCyiPC2Xs1VMQlhsga05wAAAlk"]
[Mon Jun 15 20:18:48.787951 2026] [security2:error] [pid 53359:tid 53512] [client 103.20.126.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.travelmax.in"] [uri "/index.php"] [unique_id "ajCyiPC2Xs1VMQlhsga05gACJQg"]
[Mon Jun 15 20:18:48.831311 2026] [security2:error] [pid 53359:tid 53548] [client 103.125.146.66:27113] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-admin/js/chosen.php"] [unique_id "ajCyiPC2Xs1VMQlhsga09gAAAkk"]
[Mon Jun 15 20:18:48.972569 2026] [security2:error] [pid 53359:tid 53613] [client 57.141.14.111:32260] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rohandasgupta.com"] [uri "/index.php"] [unique_id "ajCyiPC2Xs1VMQlhsga07gACing"]
[Mon Jun 15 20:18:49.066483 2026] [security2:error] [pid 51003:tid 51209] [client 57.141.14.74:52564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fifthestate.agency"] [uri "/index.php"] [unique_id "ajCyiMpsKyvb75pkSvaXXQAB21E"]
[Mon Jun 15 20:18:49.219357 2026] [security2:error] [pid 51003:tid 51162] [client 103.125.146.50:53735] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/certificates/"] [unique_id "ajCyicpsKyvb75pkSvaXcgAAAaw"]
[Mon Jun 15 20:18:49.619436 2026] [security2:error] [pid 51003:tid 51207] [client 103.125.146.57:47091] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/themes/twentynineteen/sass/forms/"] [unique_id "ajCyicpsKyvb75pkSvaXfAAAAdk"]
[Mon Jun 15 20:18:49.700463 2026] [security2:error] [pid 53359:tid 53555] [client 126.209.47.75:59215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.47.209.126.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nxtal.com"] [uri "/xmlrpc.php"] [unique_id "ajCyifC2Xs1VMQlhsga1GAAAAlA"]
[Mon Jun 15 20:18:49.700607 2026] [security2:error] [pid 53359:tid 53555] [client 126.209.47.75:59215] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nxtal.com"] [uri "/xmlrpc.php"] [unique_id "ajCyifC2Xs1VMQlhsga1GAAAAlA"]
[Mon Jun 15 20:18:49.798056 2026] [security2:error] [pid 53359:tid 53572] [client 65.111.30.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.procrastinatingworker.imcorp.in"] [uri "/index.php"] [unique_id "ajCyifC2Xs1VMQlhsga1FwAAAmE"]
[Mon Jun 15 20:18:49.928392 2026] [security2:error] [pid 53359:tid 53381] [remote 194.32.155.65:33354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.155.32.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balador.in"] [uri "/wp-login.php"] [unique_id "ajCyifC2Xs1VMQlhsga1HQACPg8"]
[Mon Jun 15 20:18:49.988851 2026] [security2:error] [pid 51003:tid 51142] [client 103.125.146.41:51637] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/Text/Diff/Engine/template-singl-portfolio.php"] [unique_id "ajCyicpsKyvb75pkSvaXjQAAAZg"]
[Mon Jun 15 20:18:50.135281 2026] [security2:error] [pid 53359:tid 53459] [remote 194.32.155.65:33354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.155.32.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balador.in"] [uri "/wp-login.php"] [unique_id "ajCyivC2Xs1VMQlhsga1JwACaV0"], referer: https://balador.in/wp-login.php
[Mon Jun 15 20:18:50.224177 2026] [security2:error] [pid 53359:tid 53590] [client 54.88.254.157:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCyivC2Xs1VMQlhsga1IwACc0w"]
[Mon Jun 15 20:18:50.241869 2026] [security2:error] [pid 51003:tid 51205] [client 192.140.64.94:29983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.64.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCyispsKyvb75pkSvaXmQAAAdc"]
[Mon Jun 15 20:18:50.247134 2026] [security2:error] [pid 51003:tid 51205] [client 192.140.64.94:29983] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCyispsKyvb75pkSvaXmQAAAdc"]
[Mon Jun 15 20:18:50.341455 2026] [security2:error] [pid 51003:tid 51175] [client 47.79.206.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "societytodaynews.com"] [uri "/index.php"] [unique_id "ajCyispsKyvb75pkSvaXkgAAAbk"], referer: https://www.google.com/
[Mon Jun 15 20:18:50.423222 2026] [security2:error] [pid 51003:tid 51152] [client 103.125.146.43:53345] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-admin/users.php"] [unique_id "ajCyispsKyvb75pkSvaXngAAAaI"]
[Mon Jun 15 20:18:50.499057 2026] [security2:error] [pid 53359:tid 53552] [client 5.255.231.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyivC2Xs1VMQlhsga1LQAAAk0"]
[Mon Jun 15 20:18:50.501825 2026] [security2:error] [pid 53359:tid 53512] [client 5.255.231.61:40232] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyivC2Xs1VMQlhsga1KgACJWg"]
[Mon Jun 15 20:18:50.633475 2026] [security2:error] [pid 51003:tid 51158] [client 57.141.14.39:45438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyispsKyvb75pkSvaXpQABqCw"]
[Mon Jun 15 20:18:50.816143 2026] [security2:error] [pid 51003:tid 51197] [client 103.125.146.58:58399] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/customize/222.php"] [unique_id "ajCyispsKyvb75pkSvaXvgAAAc8"]
[Mon Jun 15 20:18:50.926396 2026] [security2:error] [pid 51003:tid 51076] [remote 91.146.99.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.99.146.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brainstrom.org"] [uri "/wp-login.php"] [unique_id "ajCyispsKyvb75pkSvaXwAACBkg"]
[Mon Jun 15 20:18:50.950872 2026] [security2:error] [pid 53359:tid 53447] [remote 74.7.227.173:42792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.rentswale.ehx.czu.mybluehostin.me"] [uri "/fonts/images/js/images/css/admin/uploads/source/img/subcategory.php"] [unique_id "ajCyivC2Xs1VMQlhsga1NwACKlE"], referer: https://www.rentswale.ehx.czu.mybluehostin.me/fonts/images/js/images/css/admin/uploads/source/img/upi.png
[Mon Jun 15 20:18:50.959901 2026] [security2:error] [pid 51003:tid 51242] [client 240.203.218.148:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCyispsKyvb75pkSvaXogAB_CE"], referer: https://mywordsnthoughts.com/mazha-song-from-shikkari-shambhu-lyrics-in-english-with-translation/
[Mon Jun 15 20:18:51.002985 2026] [security2:error] [pid 51003:tid 51071] [remote 240.203.218.148:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCyispsKyvb75pkSvaXpAABwEM"], referer: https://mywordsnthoughts.com/mazha-song-from-shikkari-shambhu-lyrics-in-english-with-translation/
[Mon Jun 15 20:18:51.212373 2026] [security2:error] [pid 51003:tid 51255] [client 103.125.146.69:55321] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/languages/autoload_classmap.php"] [unique_id "ajCyi8psKyvb75pkSvaXxwAAAgk"]
[Mon Jun 15 20:18:51.423445 2026] [security2:error] [pid 53359:tid 53572] [client 143.244.57.120:50456] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.surveylaya.com"] [uri "/wp-content/upgrade/"] [unique_id "ajCyi_C2Xs1VMQlhsga1RAAAAmE"]
[Mon Jun 15 20:18:51.496103 2026] [security2:error] [pid 53359:tid 53448] [remote 91.146.99.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.99.146.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brainstrom.org"] [uri "/wp-login.php"] [unique_id "ajCyi_C2Xs1VMQlhsga1SAACS1I"], referer: https://brainstrom.org/wp-login.php
[Mon Jun 15 20:18:51.635843 2026] [security2:error] [pid 51003:tid 51137] [client 103.125.146.64:51779] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/blocks/group/"] [unique_id "ajCyi8psKyvb75pkSvaX0QAAAZM"]
[Mon Jun 15 20:18:51.689092 2026] [lsapi:error] [pid 51003:tid 51049] [remote 103.108.146.15:0] [host www.kthemani.com] Error on sending request(GET /en/products/3849482/ HTTP/2.0); uri(/index.php) content-length(0): ReceiveAckHdr: nothing to read from backend (LVE ID 1402; user ID 1402), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html
[Mon Jun 15 20:18:51.718506 2026] [security2:error] [pid 53359:tid 53575] [client 95.108.213.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyi_C2Xs1VMQlhsga1TgAAAmQ"]
[Mon Jun 15 20:18:51.727260 2026] [security2:error] [pid 51003:tid 51174] [client 95.108.213.122:34934] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyi8psKyvb75pkSvaXzwABuHw"]
[Mon Jun 15 20:18:52.025546 2026] [security2:error] [pid 53359:tid 53568] [client 103.125.146.60:46069] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/uploads/wp-load.php"] [unique_id "ajCyjPC2Xs1VMQlhsga1WAAAAl0"]
[Mon Jun 15 20:18:52.416008 2026] [security2:error] [pid 51003:tid 51209] [client 103.125.146.48:65153] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/js/dist"] [unique_id "ajCyjMpsKyvb75pkSvaX4QAAAds"]
[Mon Jun 15 20:18:52.795290 2026] [security2:error] [pid 51003:tid 51135] [client 103.125.146.70:56611] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/certificates/autoload_classmap.php"] [unique_id "ajCyjMpsKyvb75pkSvaX8wAAAZE"]
[Mon Jun 15 20:18:52.801810 2026] [security2:error] [pid 53359:tid 53592] [client 213.180.203.93:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyjPC2Xs1VMQlhsga1bAAAAnU"]
[Mon Jun 15 20:18:52.809360 2026] [security2:error] [pid 53359:tid 53541] [client 213.180.203.93:42098] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyjPC2Xs1VMQlhsga1ZgACQlo"]
[Mon Jun 15 20:18:53.219136 2026] [security2:error] [pid 53359:tid 53548] [client 103.125.146.59:31169] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/sodium_compat/"] [unique_id "ajCyjfC2Xs1VMQlhsga1gwAAAkk"]
[Mon Jun 15 20:18:53.328922 2026] [security2:error] [pid 53359:tid 53557] [client 45.84.107.74:60249] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "gamergreatness.com"] [uri "/index.php"] [unique_id "ajCyjfC2Xs1VMQlhsga1eQACUmQ"], referer: https://gamergreatness.com/gta-6-rumors-and-official-details
[Mon Jun 15 20:18:53.361551 2026] [security2:error] [pid 53359:tid 53444] [remote 89.58.31.106:57436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.31.58.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ektagroup.org"] [uri "/wp-login.php"] [unique_id "ajCyjfC2Xs1VMQlhsga1igACWU4"]
[Mon Jun 15 20:18:53.655163 2026] [security2:error] [pid 53359:tid 53399] [remote 89.58.31.106:57436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.31.58.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ektagroup.org"] [uri "/wp-login.php"] [unique_id "ajCyjfC2Xs1VMQlhsga1mwACjyE"], referer: https://ektagroup.org/wp-login.php
[Mon Jun 15 20:18:53.744047 2026] [security2:error] [pid 53359:tid 53608] [client 47.79.201.214:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "societytodaynews.com"] [uri "/index.php"] [unique_id "ajCyjfC2Xs1VMQlhsga1kwAAAoU"], referer: https://www.google.com/
[Mon Jun 15 20:18:53.789154 2026] [security2:error] [pid 53359:tid 53397] [remote 111.225.148.244:63154] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "puzzleadventureguide.com"] [uri "/"] [unique_id "ajCyjfC2Xs1VMQlhsga1ngACMB8"]
[Mon Jun 15 20:18:53.867005 2026] [security2:error] [pid 53359:tid 53535] [client 87.250.224.202:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyjfC2Xs1VMQlhsga1owAAAjw"]
[Mon Jun 15 20:18:53.958005 2026] [security2:error] [pid 53359:tid 53526] [client 87.250.224.202:50750] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyjfC2Xs1VMQlhsga1nQACM3w"]
[Mon Jun 15 20:18:53.973387 2026] [security2:error] [pid 51003:tid 51054] [remote 184.107.244.93:33832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.244.107.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "societytodaynews.com"] [uri "/wp-login.php"] [unique_id "ajCyjcpsKyvb75pkSvaYGQACAjI"]
[Mon Jun 15 20:18:54.167147 2026] [security2:error] [pid 51003:tid 51047] [remote 184.107.244.93:33832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.244.107.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "societytodaynews.com"] [uri "/wp-login.php"] [unique_id "ajCyjspsKyvb75pkSvaYHQABkSs"], referer: https://societytodaynews.com/wp-login.php
[Mon Jun 15 20:18:54.229566 2026] [security2:error] [pid 53359:tid 53537] [client 57.141.14.103:45054] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyjvC2Xs1VMQlhsga1qgACPlA"]
[Mon Jun 15 20:18:54.270394 2026] [security2:error] [pid 53359:tid 53555] [client 57.141.14.64:47842] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyjvC2Xs1VMQlhsga1qwACUFs"]
[Mon Jun 15 20:18:54.611218 2026] [security2:error] [pid 53359:tid 53441] [remote 84.33.224.238:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "vishalsarang.com"] [uri "/wp-content/plugins/updraftplus/readme.txt"] [unique_id "ajCyjvC2Xs1VMQlhsga1wAACFUs"]
[Mon Jun 15 20:18:54.698502 2026] [security2:error] [pid 53359:tid 53472] [remote 74.208.140.41:57650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.140.208.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hydlab.co.in"] [uri "/wp-login.php"] [unique_id "ajCyjvC2Xs1VMQlhsga1wwACLWo"]
[Mon Jun 15 20:18:54.739782 2026] [security2:error] [pid 53359:tid 53605] [client 103.125.146.30:30113] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/class-wp-site-edit.php"] [unique_id "ajCyjvC2Xs1VMQlhsga1xwAAAoI"]
[Mon Jun 15 20:18:54.853976 2026] [security2:error] [pid 53359:tid 53602] [client 206.189.83.14:63498] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ukshopfronts.co.uk"] [uri "/wp-content/plugins/wps-hide-login/wps-hide-login.php"] [unique_id "ajCyjvC2Xs1VMQlhsga1ywAAAn8"]
[Mon Jun 15 20:18:54.857026 2026] [security2:error] [pid 51003:tid 51197] [client 131.108.86.155:37651] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "wantpg.com"] [uri "/public/index.php/pg-in-novaya-roshcha-2144169"] [unique_id "ajCyjspsKyvb75pkSvaYLQAAAc8"]
[Mon Jun 15 20:18:54.881745 2026] [security2:error] [pid 53359:tid 53483] [remote 74.208.140.41:57650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.140.208.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hydlab.co.in"] [uri "/wp-login.php"] [unique_id "ajCyjvC2Xs1VMQlhsga1zAACUXU"], referer: https://hydlab.co.in/wp-login.php
[Mon Jun 15 20:18:54.921799 2026] [security2:error] [pid 53359:tid 53609] [client 57.141.14.101:64424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyjvC2Xs1VMQlhsga1yAAChgI"]
[Mon Jun 15 20:18:55.025694 2026] [security2:error] [pid 53359:tid 53543] [client 87.250.224.211:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyjvC2Xs1VMQlhsga11QAAAkQ"]
[Mon Jun 15 20:18:55.066045 2026] [security2:error] [pid 53359:tid 53549] [client 87.250.224.211:46204] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCyjvC2Xs1VMQlhsga1zgACShY"]
[Mon Jun 15 20:18:55.101721 2026] [security2:error] [pid 51003:tid 51137] [client 103.125.146.37:24153] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/uploads/wp-sync-db/admin.php"] [unique_id "ajCyj8psKyvb75pkSvaYNQAAAZM"]
[Mon Jun 15 20:18:55.431369 2026] [security2:error] [pid 53359:tid 53377] [remote 45.84.107.74:1749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.107.84.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gamergreatness.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ajCyj_C2Xs1VMQlhsga14QACIws"], referer: https://gamergreatness.com/wp-admin/admin-ajax.php?action=wpdAddSubscription
[Mon Jun 15 20:18:55.521802 2026] [security2:error] [pid 51003:tid 51174] [client 103.125.146.49:34535] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/aaa.php"] [unique_id "ajCyj8psKyvb75pkSvaYOwAAAbg"]
[Mon Jun 15 20:18:55.912178 2026] [security2:error] [pid 53359:tid 53527] [client 103.125.146.68:40651] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/system.php"] [unique_id "ajCyj_C2Xs1VMQlhsga17wAAAjQ"]
[Mon Jun 15 20:18:56.125713 2026] [security2:error] [pid 51003:tid 51248] [client 213.180.203.152:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCykMpsKyvb75pkSvaYSwAAAgI"]
[Mon Jun 15 20:18:56.128545 2026] [security2:error] [pid 53359:tid 53514] [client 213.180.203.152:42758] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCykPC2Xs1VMQlhsga1-AACJ1w"]
[Mon Jun 15 20:18:56.260414 2026] [security2:error] [pid 53359:tid 53541] [client 57.141.14.94:46820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCykPC2Xs1VMQlhsga1_wACQmE"]
[Mon Jun 15 20:18:56.269133 2026] [security2:error] [pid 51003:tid 51177] [client 139.99.122.191:53814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.122.99.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srinivasgorthyandco.com"] [uri "/wp-login.php"] [unique_id "ajCykMpsKyvb75pkSvaYTgAAAbs"]
[Mon Jun 15 20:18:56.288233 2026] [security2:error] [pid 53359:tid 53535] [client 103.125.146.37:33921] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-admin/config.php"] [unique_id "ajCykPC2Xs1VMQlhsga2AgAAAjw"]
[Mon Jun 15 20:18:56.553741 2026] [security2:error] [pid 51003:tid 51157] [client 31.219.209.201:53650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.209.219.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCykMpsKyvb75pkSvaYVAAAAac"]
[Mon Jun 15 20:18:56.553905 2026] [security2:error] [pid 51003:tid 51157] [client 31.219.209.201:53650] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCykMpsKyvb75pkSvaYVAAAAac"]
[Mon Jun 15 20:18:56.709248 2026] [security2:error] [pid 53359:tid 53524] [client 139.99.122.191:54052] ModSecurity: Access denied with code 406 (phase 1). Pattern match "xmlrpc\\\\.php" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "73"] [id "392331"] [rev "3"] [msg "Atomicorp.com WAF Rules: xmlrpc DOS attack"] [severity "CRITICAL"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCykPC2Xs1VMQlhsga2EgAAAjE"]
[Mon Jun 15 20:18:56.709390 2026] [security2:error] [pid 53359:tid 53524] [client 139.99.122.191:54052] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCykPC2Xs1VMQlhsga2EgAAAjE"]
[Mon Jun 15 20:18:56.716776 2026] [security2:error] [pid 53359:tid 53615] [client 103.125.146.41:33505] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/SimplePie/allfa.php"] [unique_id "ajCykPC2Xs1VMQlhsga2EwAAAow"]
[Mon Jun 15 20:18:57.070485 2026] [security2:error] [pid 51003:tid 51260] [client 104.207.43.28:53015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.43.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rajunandkardeputycollector.blog"] [uri "/wp-login.php"] [unique_id "ajCykcpsKyvb75pkSvaYYwAAAg4"], referer: https://rajunandkardeputycollector.blog/wp-login.php
[Mon Jun 15 20:18:57.126887 2026] [security2:error] [pid 51003:tid 51151] [client 103.125.146.50:51503] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-admin/wp-config-backup.php"] [unique_id "ajCykcpsKyvb75pkSvaYZQAAAaE"]
[Mon Jun 15 20:18:57.320482 2026] [security2:error] [pid 51003:tid 51210] [client 66.249.79.226:48898] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.majividyarthikes.com"] [uri "/index.php"] [unique_id "ajCykcpsKyvb75pkSvaYZAAAAdw"]
[Mon Jun 15 20:18:57.441058 2026] [security2:error] [pid 53359:tid 53478] [remote 69.57.172.207:55058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.172.57.69.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healingessence.in"] [uri "/wp-login.php"] [unique_id "ajCykfC2Xs1VMQlhsga2LgACWXA"]
[Mon Jun 15 20:18:57.517193 2026] [security2:error] [pid 53359:tid 53549] [client 103.163.220.5:54419] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/blocks/config.php"] [unique_id "ajCykfC2Xs1VMQlhsga2MgAAAko"]
[Mon Jun 15 20:18:57.560781 2026] [security2:error] [pid 53359:tid 53610] [client 86.153.242.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "studioforge.ae"] [uri "/index.php"] [unique_id "ajCykfC2Xs1VMQlhsga2IwAAAoc"]
[Mon Jun 15 20:18:57.621875 2026] [security2:error] [pid 51003:tid 51125] [remote 188.166.231.216:53156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.231.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avikatechnologies.com"] [uri "/wp-login.php"] [unique_id "ajCykcpsKyvb75pkSvaYcgAB-3k"]
[Mon Jun 15 20:18:57.789942 2026] [security2:error] [pid 53359:tid 53519] [client 47.79.201.120:38140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.201.79.47.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gpgaya.org"] [uri "/index.php/home/tranning"] [unique_id "ajCykfC2Xs1VMQlhsga2OwAAAiw"], referer: https://www.google.com/
[Mon Jun 15 20:18:57.904387 2026] [security2:error] [pid 51003:tid 51166] [client 57.141.14.84:22630] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fifthestate.agency"] [uri "/index.php"] [unique_id "ajCykcpsKyvb75pkSvaYbwABsH4"]
[Mon Jun 15 20:18:57.914652 2026] [security2:error] [pid 53359:tid 53384] [remote 69.57.172.207:55058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.172.57.69.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healingessence.in"] [uri "/wp-login.php"] [unique_id "ajCykfC2Xs1VMQlhsga2QQAChBI"], referer: https://healingessence.in/wp-login.php
[Mon Jun 15 20:18:57.931394 2026] [security2:error] [pid 51003:tid 51217] [client 103.125.146.59:32637] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/well-known/config.php"] [unique_id "ajCykcpsKyvb75pkSvaYeQAAAeM"]
[Mon Jun 15 20:18:58.024146 2026] [security2:error] [pid 51003:tid 51025] [remote 188.166.231.216:53156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.231.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avikatechnologies.com"] [uri "/wp-login.php"] [unique_id "ajCykspsKyvb75pkSvaYfAAB2hU"], referer: https://avikatechnologies.com/wp-login.php
[Mon Jun 15 20:18:58.141059 2026] [security2:error] [pid 53359:tid 53467] [remote 57.141.14.85:47864] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCykvC2Xs1VMQlhsga2SQACUGU"]
[Mon Jun 15 20:18:58.319658 2026] [security2:error] [pid 53359:tid 53526] [client 103.125.146.80:25975] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/updraft/"] [unique_id "ajCykvC2Xs1VMQlhsga2UwAAAjM"]
[Mon Jun 15 20:18:58.615037 2026] [security2:error] [pid 53359:tid 53513] [client 181.192.93.194:37948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "newsymcon.symcon.in"] [uri "/xmlrpc.php"] [unique_id "ajCykvC2Xs1VMQlhsga2VgAAAiY"]
[Mon Jun 15 20:18:58.618800 2026] [core:error] [pid 53359:tid 53369] [remote 77.91.96.90:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jun 15 20:18:58.618817 2026] [core:error] [pid 53359:tid 53369] [remote 77.91.96.90:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jun 15 20:18:58.664501 2026] [security2:error] [pid 53359:tid 53551] [client 139.99.122.191:54346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.122.99.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srinivasgorthyandco.com"] [uri "/wp-login.php"] [unique_id "ajCykvC2Xs1VMQlhsga2XgAAAkw"]
[Mon Jun 15 20:18:58.710752 2026] [security2:error] [pid 53359:tid 53560] [client 103.125.146.79:56363] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/w3tc-config/"] [unique_id "ajCykvC2Xs1VMQlhsga2YQAAAlU"]
[Mon Jun 15 20:18:58.726814 2026] [security2:error] [pid 51003:tid 51023] [remote 47.128.33.101:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mywordsnthoughts.com"] [uri "/kerala-is-famous-for-variety-of-breakfast-items/"] [unique_id "ajCykspsKyvb75pkSvaYjgABxBM"]
[Mon Jun 15 20:18:58.867827 2026] [security2:error] [pid 53359:tid 53383] [remote 162.254.36.150:43006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.36.254.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rkfreshmart.net"] [uri "/wp-login.php"] [unique_id "ajCykvC2Xs1VMQlhsga2ZQACbhE"]
[Mon Jun 15 20:18:58.978965 2026] [security2:error] [pid 51003:tid 51146] [client 139.99.122.191:54450] ModSecurity: Access denied with code 406 (phase 1). Pattern match "xmlrpc\\\\.php" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "73"] [id "392331"] [rev "3"] [msg "Atomicorp.com WAF Rules: xmlrpc DOS attack"] [severity "CRITICAL"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCykspsKyvb75pkSvaYjwAAAZw"]
[Mon Jun 15 20:18:58.979099 2026] [security2:error] [pid 51003:tid 51146] [client 139.99.122.191:54450] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCykspsKyvb75pkSvaYjwAAAZw"]
[Mon Jun 15 20:18:58.998112 2026] [security2:error] [pid 53359:tid 53548] [client 139.99.122.191:54448] ModSecurity: Access denied with code 406 (phase 1). Pattern match "xmlrpc\\\\.php" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "73"] [id "392331"] [rev "3"] [msg "Atomicorp.com WAF Rules: xmlrpc DOS attack"] [severity "CRITICAL"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCykvC2Xs1VMQlhsga2bAAAAkk"]
[Mon Jun 15 20:18:58.998211 2026] [security2:error] [pid 53359:tid 53548] [client 139.99.122.191:54448] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCykvC2Xs1VMQlhsga2bAAAAkk"]
[Mon Jun 15 20:18:59.127372 2026] [security2:error] [pid 51003:tid 51193] [client 103.125.146.63:36951] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/upgrade-temp-backup/config.php"] [unique_id "ajCyk8psKyvb75pkSvaYmAAAAcs"]
[Mon Jun 15 20:18:59.210627 2026] [security2:error] [pid 53359:tid 53481] [remote 162.254.36.150:43006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.36.254.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rkfreshmart.net"] [uri "/wp-login.php"] [unique_id "ajCyk_C2Xs1VMQlhsga2eAACF3M"], referer: https://rkfreshmart.net/wp-login.php
[Mon Jun 15 20:18:59.323623 2026] [security2:error] [pid 53359:tid 53575] [client 57.141.14.92:60978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyk_C2Xs1VMQlhsga2dgACZAY"]
[Mon Jun 15 20:18:59.364805 2026] [security2:error] [pid 53359:tid 53542] [client 65.111.30.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.procrastinatingworker.imcorp.in"] [uri "/index.php"] [unique_id "ajCyk_C2Xs1VMQlhsga2fgAAAkM"]
[Mon Jun 15 20:18:59.525094 2026] [security2:error] [pid 53359:tid 53506] [client 109.106.142.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kthemani.com"] [uri "/index.php"] [unique_id "ajCykfC2Xs1VMQlhsga2NQACHys"]
[Mon Jun 15 20:18:59.545665 2026] [security2:error] [pid 53359:tid 53576] [client 103.125.146.54:47467] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/js/jcrop/wp-cron.php"] [unique_id "ajCyk_C2Xs1VMQlhsga2jgAAAmU"]
[Mon Jun 15 20:18:59.795445 2026] [security2:error] [pid 53359:tid 53594] [client 139.99.122.191:54626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.122.99.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srinivasgorthyandco.com"] [uri "/wp-login.php"] [unique_id "ajCyk_C2Xs1VMQlhsga2mgAAAnc"]
[Mon Jun 15 20:18:59.799141 2026] [security2:error] [pid 53359:tid 53578] [client 139.99.122.191:54630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.122.99.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srinivasgorthyandco.com"] [uri "/wp-login.php"] [unique_id "ajCyk_C2Xs1VMQlhsga2mwAAAmc"]
[Mon Jun 15 20:19:00.000867 2026] [security2:error] [pid 51003:tid 51136] [client 103.125.146.41:59533] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-admin/images/as.php"] [unique_id "ajCylMpsKyvb75pkSvaYqwAAAZI"]
[Mon Jun 15 20:19:00.192819 2026] [security2:error] [pid 53359:tid 53484] [remote 103.127.30.137:50154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.30.127.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "growbizzz.com"] [uri "/wp-login.php"] [unique_id "ajCylPC2Xs1VMQlhsga2oQACUHY"]
[Mon Jun 15 20:19:00.222939 2026] [security2:error] [pid 53359:tid 53593] [client 121.229.156.88:46912] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.diggysguide.com"] [uri "/halloween-2021/city-power-plant"] [unique_id "ajCylPC2Xs1VMQlhsga2pQAAAnY"]
[Mon Jun 15 20:19:00.223027 2026] [security2:error] [pid 53359:tid 53593] [client 121.229.156.88:46912] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.diggysguide.com"] [uri "/halloween-2021/city-power-plant"] [unique_id "ajCylPC2Xs1VMQlhsga2pQAAAnY"]
[Mon Jun 15 20:19:00.229792 2026] [security2:error] [pid 51003:tid 51117] [remote 124.156.212.23:4585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.212.156.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wafflemenu.onl"] [uri "/wp-login.php"] [unique_id "ajCylMpsKyvb75pkSvaYsQABwnE"]
[Mon Jun 15 20:19:00.385785 2026] [security2:error] [pid 53359:tid 53564] [client 126.209.47.75:59713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.47.209.126.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nxtal.com"] [uri "/xmlrpc.php"] [unique_id "ajCylPC2Xs1VMQlhsga2rQAAAlk"]
[Mon Jun 15 20:19:00.385923 2026] [security2:error] [pid 53359:tid 53564] [client 126.209.47.75:59713] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nxtal.com"] [uri "/xmlrpc.php"] [unique_id "ajCylPC2Xs1VMQlhsga2rQAAAlk"]
[Mon Jun 15 20:19:00.388539 2026] [security2:error] [pid 53359:tid 53539] [client 103.125.146.39:63791] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/languages/classwithtostring.php"] [unique_id "ajCylPC2Xs1VMQlhsga2rgAAAkA"]
[Mon Jun 15 20:19:00.402261 2026] [security2:error] [pid 51003:tid 51236] [client 69.63.184.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "burgerking-menu.com"] [uri "/index.php"] [unique_id "ajCylMpsKyvb75pkSvaYtQAAAfY"]
[Mon Jun 15 20:19:00.740425 2026] [security2:error] [pid 53359:tid 53495] [client 192.140.64.94:29862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.64.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCylPC2Xs1VMQlhsga2uQAAAhQ"]
[Mon Jun 15 20:19:00.740571 2026] [security2:error] [pid 53359:tid 53495] [client 192.140.64.94:29862] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCylPC2Xs1VMQlhsga2uQAAAhQ"]
[Mon Jun 15 20:19:00.779190 2026] [security2:error] [pid 53359:tid 53512] [client 57.141.14.108:36449] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCylPC2Xs1VMQlhsga2tgACJVU"]
[Mon Jun 15 20:19:00.792847 2026] [security2:error] [pid 51003:tid 51201] [client 103.125.146.48:23243] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/maintenance/"] [unique_id "ajCylMpsKyvb75pkSvaYzQAAAdM"]
[Mon Jun 15 20:19:01.010887 2026] [security2:error] [pid 53359:tid 53612] [client 57.141.14.108:36459] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fifthestate.agency"] [uri "/index.php"] [unique_id "ajCylPC2Xs1VMQlhsga2uwACiRs"]
[Mon Jun 15 20:19:01.057273 2026] [security2:error] [pid 51003:tid 51169] [client 104.238.49.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vishalsarang.com"] [uri "/index.php"] [unique_id "ajCykspsKyvb75pkSvaYiAABszs"]
[Mon Jun 15 20:19:01.076290 2026] [security2:error] [pid 53359:tid 53382] [remote 103.127.30.137:50154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.30.127.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "growbizzz.com"] [uri "/wp-login.php"] [unique_id "ajCylfC2Xs1VMQlhsga20wACXBA"], referer: https://growbizzz.com/wp-login.php
[Mon Jun 15 20:19:01.209420 2026] [security2:error] [pid 53359:tid 53595] [client 103.125.146.80:58521] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/66.php"] [unique_id "ajCylfC2Xs1VMQlhsga22gAAAng"]
[Mon Jun 15 20:19:01.249670 2026] [security2:error] [pid 53359:tid 53520] [client 57.141.14.49:39193] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "majividyarthikes.com"] [uri "/index.php"] [unique_id "ajCylPC2Xs1VMQlhsga2zQACLQU"]
[Mon Jun 15 20:19:01.606122 2026] [security2:error] [pid 53359:tid 53531] [client 103.125.146.37:34757] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-admin/admin-post-interpreter.php"] [unique_id "ajCylfC2Xs1VMQlhsga25QAAAjg"]
[Mon Jun 15 20:19:02.006668 2026] [security2:error] [pid 53359:tid 53585] [client 103.125.146.78:22747] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/fonts/"] [unique_id "ajCylvC2Xs1VMQlhsga27gAAAm4"]
[Mon Jun 15 20:19:02.288968 2026] [security2:error] [pid 51003:tid 51250] [client 181.192.93.194:38664] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "newsymcon.symcon.in"] [uri "/xmlrpc.php"] [unique_id "ajCylspsKyvb75pkSvaZBQAAAgQ"]
[Mon Jun 15 20:19:02.312028 2026] [security2:error] [pid 51003:tid 51006] [remote 89.58.31.106:60780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.31.58.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cafeinnovation.in"] [uri "/wp-login.php"] [unique_id "ajCylspsKyvb75pkSvaZCAAB9gI"]
[Mon Jun 15 20:19:02.391492 2026] [security2:error] [pid 51003:tid 51197] [client 103.125.146.31:60333] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/cgi-bin/wp-conflg.php"] [unique_id "ajCylspsKyvb75pkSvaZDAAAAc8"]
[Mon Jun 15 20:19:02.439110 2026] [security2:error] [pid 53359:tid 53550] [client 57.141.14.83:25958] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCylvC2Xs1VMQlhsga2-gACS1c"]
[Mon Jun 15 20:19:02.540646 2026] [security2:error] [pid 53359:tid 53509] [client 57.141.14.53:38584] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "majividyarthikes.com"] [uri "/index.php"] [unique_id "ajCylvC2Xs1VMQlhsga29wACIjM"]
[Mon Jun 15 20:19:02.581256 2026] [security2:error] [pid 51003:tid 51017] [remote 89.58.31.106:60780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.31.58.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cafeinnovation.in"] [uri "/wp-login.php"] [unique_id "ajCylspsKyvb75pkSvaZEAABnA0"], referer: https://cafeinnovation.in/wp-login.php
[Mon Jun 15 20:19:02.788668 2026] [security2:error] [pid 53359:tid 53539] [client 103.125.146.59:40147] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/html-api/chosen.php"] [unique_id "ajCylvC2Xs1VMQlhsga3DAAAAkA"]
[Mon Jun 15 20:19:02.792798 2026] [security2:error] [pid 51003:tid 51154] [client 65.111.30.222:14237] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.procrastinatingworker.imcorp.in"] [uri "/index.php"] [unique_id "ajCylspsKyvb75pkSvaZFgAAAaQ"]
[Mon Jun 15 20:19:02.976661 2026] [security2:error] [pid 53359:tid 53546] [client 185.198.37.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vishalsarang.com"] [uri "/index.php"] [unique_id "ajCylvC2Xs1VMQlhsga3CwACR0c"]
[Mon Jun 15 20:19:03.185527 2026] [security2:error] [pid 53359:tid 53523] [client 103.125.146.78:27805] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-admin/wp-conflg.php"] [unique_id "ajCyl_C2Xs1VMQlhsga3GwAAAjA"]
[Mon Jun 15 20:19:03.250842 2026] [security2:error] [pid 53359:tid 53419] [remote 114.119.149.3:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mywordsnthoughts.com"] [uri "/myworld/vanitha-recipes/mushroom-soup/"] [unique_id "ajCyl_C2Xs1VMQlhsga3HAACJTU"], referer: https://mywordsnthoughts.com/myworld/mushroom-spring-onion-masala/
[Mon Jun 15 20:19:03.319453 2026] [security2:error] [pid 53359:tid 53390] [remote 74.7.227.161:43462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.shreeramsweets.co.in"] [uri "/plugins/lightgallery/js/plugins/bootstrap/js/images/blog/grid/plugins/bootstrap/js/css/counter/counter/images_scroller/images_scroller/images/stores.php"] [unique_id "ajCyl_C2Xs1VMQlhsga3HgAChBg"], referer: https://www.shreeramsweets.co.in/plugins/lightgallery/js/plugins/bootstrap/js/images/blog/grid/plugins/bootstrap/js/css/counter/counter/images_scroller/images_scroller/images/restaurant.jpg
[Mon Jun 15 20:19:03.597590 2026] [security2:error] [pid 53359:tid 53578] [client 103.125.146.75:20865] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/api.php"] [unique_id "ajCyl_C2Xs1VMQlhsga3JQAAAmc"]
[Mon Jun 15 20:19:03.639773 2026] [security2:error] [pid 51003:tid 51196] [client 157.55.39.192:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "smgl.org"] [uri "/product/gemstones/crystal-quartz/wholesale-priced-sterling-silver-certified-handmade-amethyst-crystal-quartz-pendant/"] [unique_id "ajCyl8psKyvb75pkSvaZLgAAAc4"]
[Mon Jun 15 20:19:03.715874 2026] [security2:error] [pid 53359:tid 53373] [remote 209.42.18.223:34336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nutreefarm.com"] [uri "/wp-login.php"] [unique_id "ajCyl_C2Xs1VMQlhsga3KgACHAc"]
[Mon Jun 15 20:19:03.863058 2026] [security2:error] [pid 53359:tid 53612] [client 57.141.14.85:64606] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyl_C2Xs1VMQlhsga3LQACiV4"]
[Mon Jun 15 20:19:04.002301 2026] [security2:error] [pid 53359:tid 53526] [client 103.125.146.34:56201] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-admin/panel.php"] [unique_id "ajCymPC2Xs1VMQlhsga3OwAAAjM"]
[Mon Jun 15 20:19:04.033663 2026] [security2:error] [pid 53359:tid 53515] [client 139.99.122.191:55262] ModSecurity: Access denied with code 406 (phase 1). Pattern match "xmlrpc\\\\.php" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "73"] [id "392331"] [rev "3"] [msg "Atomicorp.com WAF Rules: xmlrpc DOS attack"] [severity "CRITICAL"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCymPC2Xs1VMQlhsga3PgAAAig"]
[Mon Jun 15 20:19:04.033768 2026] [security2:error] [pid 53359:tid 53515] [client 139.99.122.191:55262] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCymPC2Xs1VMQlhsga3PgAAAig"]
[Mon Jun 15 20:19:04.099381 2026] [security2:error] [pid 53359:tid 53553] [client 77.68.87.67:62561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.87.68.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celticwavessc.ie"] [uri "/images/images/cache.php"] [unique_id "ajCymPC2Xs1VMQlhsga3QwAAAk4"], referer: www.google.com
[Mon Jun 15 20:19:04.100393 2026] [security2:error] [pid 51003:tid 51031] [remote 185.68.18.52:58430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.18.68.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nctindia.org"] [uri "/wp-login.php"] [unique_id "ajCymMpsKyvb75pkSvaZPAAB-hs"]
[Mon Jun 15 20:19:04.149923 2026] [proxy:error] [pid 51003:tid 51220] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:04.150011 2026] [proxy_http:error] [pid 51003:tid 51220] [client 142.248.80.104:63378] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:04.151356 2026] [proxy:error] [pid 51003:tid 51220] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:04.151412 2026] [proxy_http:error] [pid 51003:tid 51220] [client 142.248.80.104:63378] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:04.170164 2026] [security2:error] [pid 51003:tid 51257] [client 57.141.14.13:24659] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "majividyarthikes.com"] [uri "/index.php"] [unique_id "ajCyl8psKyvb75pkSvaZOAACCyo"]
[Mon Jun 15 20:19:04.292314 2026] [security2:error] [pid 53359:tid 53620] [client 27.60.188.98:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kthemani.com"] [uri "/index.php"] [unique_id "ajCylvC2Xs1VMQlhsga29gAAApE"]
[Mon Jun 15 20:19:04.347777 2026] [autoindex:error] [pid 51003:tid 51183] [client 143.244.57.120:0] AH01276: Cannot serve directory /home3/itjbthmy/public_html/surveylaya/wp-content/upgrade/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:19:04.348221 2026] [security2:error] [pid 51003:tid 51183] [client 143.244.57.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.surveylaya.com"] [uri "/cgi-sys/403.html"] [unique_id "ajCymMpsKyvb75pkSvaZSAAAAcE"]
[Mon Jun 15 20:19:04.350834 2026] [security2:error] [pid 53359:tid 53543] [client 143.244.57.120:59316] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.surveylaya.com"] [uri "/wp-content/upgrade/"] [unique_id "ajCymPC2Xs1VMQlhsga3SQAAAkQ"]
[Mon Jun 15 20:19:04.413058 2026] [security2:error] [pid 51003:tid 51191] [client 103.125.146.62:33991] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/wp-cron.php"] [unique_id "ajCymMpsKyvb75pkSvaZSwAAAck"]
[Mon Jun 15 20:19:04.687192 2026] [security2:error] [pid 53359:tid 53562] [client 57.141.14.62:23594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fifthestate.agency"] [uri "/index.php"] [unique_id "ajCymPC2Xs1VMQlhsga3TgACV2o"]
[Mon Jun 15 20:19:04.777605 2026] [security2:error] [pid 53359:tid 53379] [remote 57.141.14.73:39494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.14.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wilsonoverseas.com"] [uri "/items/G437035876"] [unique_id "ajCymPC2Xs1VMQlhsga3WQACHA0"]
[Mon Jun 15 20:19:04.798875 2026] [security2:error] [pid 53359:tid 53557] [client 103.125.146.54:52853] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/chand.php"] [unique_id "ajCymPC2Xs1VMQlhsga3WgAAAlI"]
[Mon Jun 15 20:19:04.823601 2026] [security2:error] [pid 53359:tid 53559] [client 57.141.14.2:47561] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCymPC2Xs1VMQlhsga3WAACVFQ"]
[Mon Jun 15 20:19:04.933689 2026] [security2:error] [pid 53359:tid 53368] [remote 31.220.84.188:50352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.84.220.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hydlab.in"] [uri "/wp-login.php"] [unique_id "ajCymPC2Xs1VMQlhsga3XgACfQI"]
[Mon Jun 15 20:19:05.060410 2026] [security2:error] [pid 53359:tid 53391] [remote 34.90.69.83:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "autodiscover.sasclinical.com"] [uri "/"] [unique_id "ajCymfC2Xs1VMQlhsga3YQACghk"]
[Mon Jun 15 20:19:05.060513 2026] [security2:error] [pid 53359:tid 53605] [client 34.90.69.83:0] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "autodiscover.sasclinical.com"] [uri "/"] [unique_id "ajCymfC2Xs1VMQlhsga3YQACghk"]
[Mon Jun 15 20:19:05.133867 2026] [security2:error] [pid 53359:tid 53418] [remote 31.220.84.188:50352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.84.220.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hydlab.in"] [uri "/wp-login.php"] [unique_id "ajCymfC2Xs1VMQlhsga3YgACiTQ"], referer: https://hydlab.in/wp-login.php
[Mon Jun 15 20:19:05.193174 2026] [security2:error] [pid 51003:tid 51048] [remote 31.3.241.131:59074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.241.3.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fredy-menu.com"] [uri "/wp-login.php"] [unique_id "ajCymcpsKyvb75pkSvaZWAABkyw"]
[Mon Jun 15 20:19:05.215082 2026] [security2:error] [pid 53359:tid 53596] [client 103.125.146.37:29959] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/licenses/images/widgets/"] [unique_id "ajCymfC2Xs1VMQlhsga3YwAAAnk"]
[Mon Jun 15 20:19:05.585172 2026] [security2:error] [pid 53359:tid 53519] [client 114.119.139.110:33737] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "radicallyeverafter.com"] [uri "/buercydw"] [unique_id "ajCymfC2Xs1VMQlhsga3cQAAAiw"], referer: http://kidsline.tv/jmyuoeiqapp
[Mon Jun 15 20:19:05.621092 2026] [security2:error] [pid 53359:tid 53620] [client 103.125.146.37:36971] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/interactivity-api/block-bindings/"] [unique_id "ajCymfC2Xs1VMQlhsga3dAAAApE"]
[Mon Jun 15 20:19:05.662342 2026] [security2:error] [pid 53359:tid 53387] [remote 74.7.227.149:38816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.shreeramsweets-co-in.xgh.ggk.mybluehostin.me"] [uri "/plugins/lightgallery/js/plugins/owl-carousel/images/blog/grid/bhaji-boxes.php"] [unique_id "ajCymfC2Xs1VMQlhsga3dQACkxU"], referer: https://www.shreeramsweets-co-in.xgh.ggk.mybluehostin.me/plugins/lightgallery/js/plugins/owl-carousel/images/blog/grid/pic2.jpg
[Mon Jun 15 20:19:05.799809 2026] [security2:error] [pid 51003:tid 51105] [remote 31.3.241.131:59074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.241.3.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fredy-menu.com"] [uri "/wp-login.php"] [unique_id "ajCymcpsKyvb75pkSvaZZQAB52U"], referer: https://fredy-menu.com/wp-login.php
[Mon Jun 15 20:19:06.033559 2026] [security2:error] [pid 51003:tid 51223] [client 103.125.146.65:23383] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/assets/certificates/"] [unique_id "ajCymspsKyvb75pkSvaZbQAAAek"]
[Mon Jun 15 20:19:06.177521 2026] [security2:error] [pid 53359:tid 53604] [client 139.99.122.191:55436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.122.99.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srinivasgorthyandco.com"] [uri "/wp-login.php"] [unique_id "ajCymvC2Xs1VMQlhsga3iwAAAoE"]
[Mon Jun 15 20:19:06.179052 2026] [security2:error] [pid 53359:tid 53471] [remote 74.7.227.178:55744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "softhubtechno.ehx.czu.mybluehostin.me"] [uri "/images/js/js/images/clients/img/Admin/logo/carrer.php"] [unique_id "ajCymvC2Xs1VMQlhsga3jQACHmk"], referer: https://softhubtechno.ehx.czu.mybluehostin.me/images/js/js/images/clients/img/Admin/logo/Screenshot%202022-06-04%20at%202.50.19%20PM.png
[Mon Jun 15 20:19:06.203692 2026] [security2:error] [pid 53359:tid 53602] [client 47.79.201.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "societytodaynews.com"] [uri "/index.php"] [unique_id "ajCymfC2Xs1VMQlhsga3fwAAAn8"], referer: https://www.google.com/
[Mon Jun 15 20:19:06.433425 2026] [security2:error] [pid 51003:tid 51128] [remote 194.32.155.65:57378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.155.32.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koyeldasguptanaha.com"] [uri "/wp-login.php"] [unique_id "ajCymspsKyvb75pkSvaZdQAB-nw"]
[Mon Jun 15 20:19:06.442824 2026] [security2:error] [pid 53359:tid 53564] [client 103.125.146.32:35311] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/PHPMailer/Newspaper/includes/"] [unique_id "ajCymvC2Xs1VMQlhsga3mwAAAlk"]
[Mon Jun 15 20:19:06.657015 2026] [security2:error] [pid 53359:tid 53519] [client 139.99.122.191:55478] ModSecurity: Access denied with code 409 (phase 1). Match of "eq 1" against "&REQUEST_COOKIES:humans_21909" required. [file "/opt/mod_security/hg_rules.conf"] [line "182"] [id "900417"] [msg "Transparent Bot Detection for Old UAs"] [hostname "srinivasgorthyandco.com"] [uri "/author/admin/"] [unique_id "ajCymvC2Xs1VMQlhsga3qAAAAiw"]
[Mon Jun 15 20:19:06.669784 2026] [security2:error] [pid 53359:tid 53534] [client 139.99.122.191:55600] ModSecurity: Access denied with code 406 (phase 1). Pattern match "xmlrpc\\\\.php" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "73"] [id "392331"] [rev "3"] [msg "Atomicorp.com WAF Rules: xmlrpc DOS attack"] [severity "CRITICAL"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCymvC2Xs1VMQlhsga3qQAAAjs"]
[Mon Jun 15 20:19:06.669961 2026] [security2:error] [pid 53359:tid 53534] [client 139.99.122.191:55600] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCymvC2Xs1VMQlhsga3qQAAAjs"]
[Mon Jun 15 20:19:06.791889 2026] [security2:error] [pid 51003:tid 51258] [client 45.3.33.135:43611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.33.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rajunandkardeputycollector.blog"] [uri "/wp-login.php"] [unique_id "ajCymspsKyvb75pkSvaZhQAAAgw"], referer: https://rajunandkardeputycollector.blog/wp-login.php
[Mon Jun 15 20:19:06.856516 2026] [security2:error] [pid 53359:tid 53554] [client 103.125.146.64:40771] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/languages/wp-content/"] [unique_id "ajCymvC2Xs1VMQlhsga3rwAAAk8"]
[Mon Jun 15 20:19:06.936390 2026] [security2:error] [pid 53359:tid 53601] [client 181.192.93.194:37124] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "newsymcon.symcon.in"] [uri "/xmlrpc.php"] [unique_id "ajCymvC2Xs1VMQlhsga3sQAAAn4"]
[Mon Jun 15 20:19:06.955119 2026] [security2:error] [pid 51003:tid 51067] [remote 57.141.14.37:57192] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCymspsKyvb75pkSvaZhwAByz8"]
[Mon Jun 15 20:19:06.957886 2026] [security2:error] [pid 51003:tid 51147] [client 47.79.201.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "societytodaynews.com"] [uri "/index.php"] [unique_id "ajCymspsKyvb75pkSvaZggAAAZ0"], referer: https://www.google.com/
[Mon Jun 15 20:19:06.978335 2026] [security2:error] [pid 53359:tid 53612] [client 193.105.134.150:54384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "gamergreatness.com"] [uri "/index.php"] [unique_id "ajCymvC2Xs1VMQlhsga3rAACiTo"], referer: https://gamergreatness.com/is-this-the-best-budget-gaming-monitor-lg-ultragear-27gl850-b-review
[Mon Jun 15 20:19:07.079064 2026] [security2:error] [pid 53359:tid 53502] [client 31.219.209.201:54259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.209.219.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCym_C2Xs1VMQlhsga3uAAAAhs"]
[Mon Jun 15 20:19:07.079296 2026] [security2:error] [pid 53359:tid 53502] [client 31.219.209.201:54259] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCym_C2Xs1VMQlhsga3uAAAAhs"]
[Mon Jun 15 20:19:07.096930 2026] [security2:error] [pid 51003:tid 51045] [remote 194.32.155.65:57378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.155.32.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koyeldasguptanaha.com"] [uri "/wp-login.php"] [unique_id "ajCym8psKyvb75pkSvaZkwAB2yk"], referer: https://koyeldasguptanaha.com/wp-login.php
[Mon Jun 15 20:19:07.298420 2026] [security2:error] [pid 51003:tid 51165] [client 54.88.94.150:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCym8psKyvb75pkSvaZkgABr3E"]
[Mon Jun 15 20:19:07.317713 2026] [security2:error] [pid 51003:tid 51189] [client 103.125.146.30:52825] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/block-bindings/wp-content/"] [unique_id "ajCym8psKyvb75pkSvaZmAAAAcc"]
[Mon Jun 15 20:19:07.318667 2026] [security2:error] [pid 51003:tid 51159] [client 45.3.37.53:44085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.37.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rajunandkardeputycollector.blog"] [uri "/wp-login.php"] [unique_id "ajCym8psKyvb75pkSvaZlgAAAak"], referer: https://rajunandkardeputycollector.blog/wp-login.php
[Mon Jun 15 20:19:07.511668 2026] [security2:error] [pid 53359:tid 53573] [client 43.173.179.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "travelmax.in"] [uri "/index.php"] [unique_id "ajCym_C2Xs1VMQlhsga3wgACYn0"]
[Mon Jun 15 20:19:07.741444 2026] [security2:error] [pid 53359:tid 53559] [client 103.125.146.47:51337] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/abilities-api/admin.php"] [unique_id "ajCym_C2Xs1VMQlhsga3yQAAAlQ"]
[Mon Jun 15 20:19:08.093370 2026] [security2:error] [pid 51003:tid 51238] [client 2a03:2880:f806:c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ruchini.hemani.finance"] [uri "/index.php"] [unique_id "ajCym8psKyvb75pkSvaZqQAB-GQ"]
[Mon Jun 15 20:19:08.122999 2026] [security2:error] [pid 51003:tid 51205] [client 116.179.32.73:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCym8psKyvb75pkSvaZpQAB1zU"]
[Mon Jun 15 20:19:08.193638 2026] [security2:error] [pid 51003:tid 51255] [client 103.125.146.47:21621] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/ai1wm-backups/koiy.php"] [unique_id "ajCynMpsKyvb75pkSvaZvAAAAgk"]
[Mon Jun 15 20:19:08.211458 2026] [security2:error] [pid 53359:tid 53618] [client 43.172.198.129:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.travelmax.in"] [uri "/index.php"] [unique_id "ajCynPC2Xs1VMQlhsga32QACj0U"]
[Mon Jun 15 20:19:08.342227 2026] [security2:error] [pid 53359:tid 53535] [client 57.141.14.108:36481] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCynPC2Xs1VMQlhsga32gACPAY"]
[Mon Jun 15 20:19:08.465208 2026] [security2:error] [pid 53359:tid 53610] [client 139.99.122.191:55734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.122.99.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srinivasgorthyandco.com"] [uri "/wp-login.php"] [unique_id "ajCynPC2Xs1VMQlhsga34AAAAoc"]
[Mon Jun 15 20:19:08.588760 2026] [security2:error] [pid 51003:tid 51239] [client 103.125.146.71:23051] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/home.php"] [unique_id "ajCynMpsKyvb75pkSvaZyQAAAfk"]
[Mon Jun 15 20:19:08.923605 2026] [security2:error] [pid 51003:tid 51169] [client 57.141.14.88:39998] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCynMpsKyvb75pkSvaZ0AABsz4"]
[Mon Jun 15 20:19:08.990049 2026] [security2:error] [pid 53359:tid 53550] [client 103.125.146.36:29635] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-admin/classwithtostring.php"] [unique_id "ajCynPC2Xs1VMQlhsga4CgAAAks"]
[Mon Jun 15 20:19:09.032653 2026] [security2:error] [pid 51003:tid 51212] [client 172.56.65.215:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kthemani.com"] [uri "/index.php"] [unique_id "ajCym8psKyvb75pkSvaZkAAB3lE"]
[Mon Jun 15 20:19:09.123499 2026] [security2:error] [pid 53359:tid 53514] [client 65.111.30.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.procrastinatingworker.imcorp.in"] [uri "/index.php"] [unique_id "ajCynfC2Xs1VMQlhsga4CwAAAic"]
[Mon Jun 15 20:19:09.151924 2026] [proxy:error] [pid 53359:tid 53605] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.151956 2026] [proxy_http:error] [pid 53359:tid 53605] [client 142.248.80.104:19900] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.152030 2026] [proxy:error] [pid 53359:tid 53587] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.152082 2026] [proxy_http:error] [pid 53359:tid 53587] [client 142.248.80.104:19912] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.152160 2026] [proxy:error] [pid 53359:tid 53583] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.152212 2026] [proxy_http:error] [pid 53359:tid 53583] [client 142.248.80.104:20098] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.152295 2026] [proxy:error] [pid 53359:tid 53575] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.152355 2026] [proxy_http:error] [pid 53359:tid 53575] [client 142.248.80.104:20102] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.152597 2026] [proxy:error] [pid 53359:tid 53605] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.152628 2026] [proxy_http:error] [pid 53359:tid 53605] [client 142.248.80.104:19900] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.152802 2026] [proxy:error] [pid 53359:tid 53569] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.152851 2026] [proxy_http:error] [pid 53359:tid 53569] [client 142.248.80.104:20082] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.152920 2026] [proxy:error] [pid 51003:tid 51246] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.152923 2026] [proxy:error] [pid 53359:tid 53583] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.152965 2026] [proxy_http:error] [pid 53359:tid 53583] [client 142.248.80.104:20098] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.152973 2026] [proxy_http:error] [pid 51003:tid 51246] [client 142.248.80.104:19990] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.153032 2026] [proxy:error] [pid 53359:tid 53587] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.153071 2026] [proxy_http:error] [pid 53359:tid 53587] [client 142.248.80.104:19912] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.153179 2026] [proxy:error] [pid 51003:tid 51210] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.153194 2026] [proxy:error] [pid 53359:tid 53581] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.153231 2026] [proxy_http:error] [pid 51003:tid 51210] [client 142.248.80.104:20050] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.153236 2026] [proxy_http:error] [pid 53359:tid 53581] [client 142.248.80.104:20018] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.153309 2026] [proxy:error] [pid 51003:tid 51149] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.153353 2026] [proxy_http:error] [pid 51003:tid 51149] [client 142.248.80.104:19982] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.153494 2026] [proxy:error] [pid 53359:tid 53543] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.153529 2026] [proxy_http:error] [pid 53359:tid 53543] [client 142.248.80.104:20068] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.153577 2026] [proxy:error] [pid 53359:tid 53569] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.153603 2026] [proxy_http:error] [pid 53359:tid 53569] [client 142.248.80.104:20082] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.153652 2026] [proxy:error] [pid 51003:tid 51246] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.153688 2026] [proxy_http:error] [pid 51003:tid 51246] [client 142.248.80.104:19990] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.153754 2026] [proxy:error] [pid 51003:tid 51150] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.153787 2026] [proxy_http:error] [pid 51003:tid 51150] [client 142.248.80.104:19922] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.153838 2026] [proxy:error] [pid 53359:tid 53577] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.153873 2026] [proxy_http:error] [pid 53359:tid 53577] [client 142.248.80.104:20042] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.153942 2026] [proxy:error] [pid 53359:tid 53581] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.153968 2026] [proxy_http:error] [pid 53359:tid 53581] [client 142.248.80.104:20018] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.154034 2026] [proxy:error] [pid 51003:tid 51210] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.154065 2026] [proxy_http:error] [pid 51003:tid 51210] [client 142.248.80.104:20050] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.154130 2026] [proxy:error] [pid 51003:tid 51149] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.154138 2026] [proxy:error] [pid 53359:tid 53575] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.154169 2026] [proxy_http:error] [pid 51003:tid 51149] [client 142.248.80.104:19982] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.154186 2026] [proxy_http:error] [pid 53359:tid 53575] [client 142.248.80.104:20102] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.154238 2026] [proxy:error] [pid 53359:tid 53543] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.154269 2026] [proxy_http:error] [pid 53359:tid 53543] [client 142.248.80.104:20068] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.154338 2026] [proxy:error] [pid 51003:tid 51245] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.154386 2026] [proxy_http:error] [pid 51003:tid 51245] [client 142.248.80.104:19936] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.154463 2026] [proxy:error] [pid 51003:tid 51177] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.154507 2026] [proxy_http:error] [pid 51003:tid 51177] [client 142.248.80.104:19892] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.154549 2026] [proxy:error] [pid 53359:tid 53577] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.154564 2026] [proxy:error] [pid 51003:tid 51150] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.154586 2026] [proxy_http:error] [pid 53359:tid 53577] [client 142.248.80.104:20042] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.154596 2026] [proxy_http:error] [pid 51003:tid 51150] [client 142.248.80.104:19922] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.154790 2026] [proxy:error] [pid 51003:tid 51243] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.154833 2026] [proxy_http:error] [pid 51003:tid 51243] [client 142.248.80.104:19888] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.155034 2026] [proxy:error] [pid 51003:tid 51245] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.155062 2026] [proxy_http:error] [pid 51003:tid 51245] [client 142.248.80.104:19936] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.155112 2026] [proxy:error] [pid 51003:tid 51140] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.155131 2026] [proxy:error] [pid 53359:tid 53595] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.155146 2026] [proxy_http:error] [pid 51003:tid 51140] [client 142.248.80.104:19932] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.155173 2026] [proxy_http:error] [pid 53359:tid 53595] [client 142.248.80.104:20060] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.155206 2026] [proxy:error] [pid 51003:tid 51177] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.155230 2026] [proxy_http:error] [pid 51003:tid 51177] [client 142.248.80.104:19892] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.155410 2026] [proxy:error] [pid 51003:tid 51136] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.155424 2026] [proxy:error] [pid 53359:tid 53618] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.155465 2026] [proxy_http:error] [pid 53359:tid 53618] [client 142.248.80.104:20030] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.155470 2026] [proxy_http:error] [pid 51003:tid 51136] [client 142.248.80.104:19966] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.155533 2026] [proxy:error] [pid 51003:tid 51243] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.155569 2026] [proxy_http:error] [pid 51003:tid 51243] [client 142.248.80.104:19888] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.155899 2026] [proxy:error] [pid 51003:tid 51140] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.155935 2026] [proxy_http:error] [pid 51003:tid 51140] [client 142.248.80.104:19932] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.155947 2026] [proxy:error] [pid 53359:tid 53595] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.155984 2026] [proxy_http:error] [pid 53359:tid 53595] [client 142.248.80.104:20060] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.156062 2026] [proxy:error] [pid 53359:tid 53588] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.156108 2026] [proxy_http:error] [pid 53359:tid 53588] [client 142.248.80.104:20044] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.156139 2026] [proxy:error] [pid 51003:tid 51200] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.156166 2026] [proxy:error] [pid 53359:tid 53564] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.156173 2026] [proxy_http:error] [pid 51003:tid 51200] [client 142.248.80.104:20250] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.156206 2026] [proxy_http:error] [pid 53359:tid 53564] [client 142.248.80.104:20008] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.156237 2026] [proxy:error] [pid 51003:tid 51136] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.156273 2026] [proxy_http:error] [pid 51003:tid 51136] [client 142.248.80.104:19966] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.156276 2026] [proxy:error] [pid 53359:tid 53618] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.156319 2026] [proxy_http:error] [pid 53359:tid 53618] [client 142.248.80.104:20030] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.156354 2026] [proxy:error] [pid 51003:tid 51210] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.156394 2026] [proxy_http:error] [pid 51003:tid 51210] [client 142.248.80.104:20168] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.156510 2026] [proxy:error] [pid 53359:tid 53526] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.156555 2026] [proxy_http:error] [pid 53359:tid 53526] [client 142.248.80.104:20004] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.156709 2026] [proxy:error] [pid 51003:tid 51200] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.156738 2026] [proxy_http:error] [pid 51003:tid 51200] [client 142.248.80.104:20250] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.156769 2026] [proxy:error] [pid 53359:tid 53588] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.156798 2026] [proxy_http:error] [pid 53359:tid 53588] [client 142.248.80.104:20044] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.156847 2026] [proxy:error] [pid 53359:tid 53555] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.156879 2026] [proxy_http:error] [pid 53359:tid 53555] [client 142.248.80.104:19950] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.156948 2026] [proxy:error] [pid 53359:tid 53602] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.156958 2026] [proxy:error] [pid 51003:tid 51210] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.156989 2026] [proxy_http:error] [pid 51003:tid 51210] [client 142.248.80.104:20168] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.156994 2026] [proxy_http:error] [pid 53359:tid 53602] [client 142.248.80.104:19962] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.157042 2026] [proxy:error] [pid 53359:tid 53564] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.157068 2026] [proxy_http:error] [pid 53359:tid 53564] [client 142.248.80.104:20008] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.157114 2026] [proxy:error] [pid 53359:tid 53519] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.157142 2026] [proxy_http:error] [pid 53359:tid 53519] [client 142.248.80.104:19906] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.157201 2026] [proxy:error] [pid 53359:tid 53535] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.157240 2026] [proxy_http:error] [pid 53359:tid 53535] [client 142.248.80.104:19890] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.157311 2026] [proxy:error] [pid 53359:tid 53526] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.157361 2026] [proxy_http:error] [pid 53359:tid 53526] [client 142.248.80.104:20004] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.157397 2026] [proxy:error] [pid 53359:tid 53555] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.157417 2026] [proxy_http:error] [pid 53359:tid 53555] [client 142.248.80.104:19950] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.157578 2026] [proxy:error] [pid 53359:tid 53519] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.157597 2026] [proxy_http:error] [pid 53359:tid 53519] [client 142.248.80.104:19906] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.157642 2026] [proxy:error] [pid 53359:tid 53602] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.157669 2026] [proxy_http:error] [pid 53359:tid 53602] [client 142.248.80.104:19962] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.157832 2026] [proxy:error] [pid 53359:tid 53535] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.157857 2026] [proxy_http:error] [pid 53359:tid 53535] [client 142.248.80.104:19890] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.243691 2026] [proxy:error] [pid 53359:tid 53531] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.243775 2026] [proxy_http:error] [pid 53359:tid 53531] [client 142.248.80.104:20200] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.244251 2026] [proxy:error] [pid 53359:tid 53531] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.244293 2026] [proxy_http:error] [pid 53359:tid 53531] [client 142.248.80.104:20200] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.245303 2026] [proxy:error] [pid 53359:tid 53576] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.245382 2026] [proxy_http:error] [pid 53359:tid 53576] [client 142.248.80.104:20278] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.245613 2026] [proxy:error] [pid 51003:tid 51192] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.245674 2026] [proxy_http:error] [pid 51003:tid 51192] [client 142.248.80.104:20262] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.245793 2026] [proxy:error] [pid 53359:tid 53546] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.245849 2026] [proxy:error] [pid 51003:tid 51234] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.245855 2026] [proxy_http:error] [pid 53359:tid 53546] [client 142.248.80.104:20268] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.245902 2026] [proxy_http:error] [pid 51003:tid 51234] [client 142.248.80.104:20224] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.245945 2026] [proxy:error] [pid 53359:tid 53515] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.245977 2026] [proxy_http:error] [pid 53359:tid 53515] [client 142.248.80.104:20276] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.246095 2026] [proxy:error] [pid 53359:tid 53576] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.246130 2026] [proxy_http:error] [pid 53359:tid 53576] [client 142.248.80.104:20278] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.246443 2026] [proxy:error] [pid 53359:tid 53512] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.246476 2026] [proxy_http:error] [pid 53359:tid 53512] [client 142.248.80.104:20252] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.246507 2026] [proxy:error] [pid 51003:tid 51192] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.246544 2026] [proxy_http:error] [pid 51003:tid 51192] [client 142.248.80.104:20262] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.246596 2026] [proxy:error] [pid 53359:tid 53542] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.246600 2026] [proxy:error] [pid 51003:tid 51208] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.246642 2026] [proxy_http:error] [pid 53359:tid 53542] [client 142.248.80.104:20298] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.246642 2026] [proxy_http:error] [pid 51003:tid 51208] [client 142.248.80.104:19612] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.246696 2026] [proxy:error] [pid 51003:tid 51234] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.246696 2026] [proxy:error] [pid 53359:tid 53515] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.246728 2026] [proxy_http:error] [pid 53359:tid 53515] [client 142.248.80.104:20276] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.246728 2026] [proxy_http:error] [pid 51003:tid 51234] [client 142.248.80.104:20224] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.246788 2026] [proxy:error] [pid 53359:tid 53546] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.246819 2026] [proxy_http:error] [pid 53359:tid 53546] [client 142.248.80.104:20268] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.246911 2026] [proxy:error] [pid 53359:tid 53495] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.246959 2026] [proxy_http:error] [pid 53359:tid 53495] [client 142.248.80.104:20212] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.247025 2026] [proxy:error] [pid 53359:tid 53539] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.247069 2026] [proxy_http:error] [pid 53359:tid 53539] [client 142.248.80.104:20236] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.247124 2026] [proxy:error] [pid 53359:tid 53552] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.247152 2026] [proxy_http:error] [pid 53359:tid 53552] [client 142.248.80.104:20292] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.247195 2026] [proxy:error] [pid 53359:tid 53512] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.247224 2026] [proxy_http:error] [pid 53359:tid 53512] [client 142.248.80.104:20252] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.247291 2026] [proxy:error] [pid 51003:tid 51208] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.247291 2026] [proxy:error] [pid 53359:tid 53542] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.247318 2026] [proxy_http:error] [pid 53359:tid 53542] [client 142.248.80.104:20298] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.247318 2026] [proxy_http:error] [pid 51003:tid 51208] [client 142.248.80.104:19612] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.247763 2026] [proxy:error] [pid 53359:tid 53539] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.247798 2026] [proxy_http:error] [pid 53359:tid 53539] [client 142.248.80.104:20236] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.247857 2026] [proxy:error] [pid 53359:tid 53552] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.247891 2026] [proxy_http:error] [pid 53359:tid 53552] [client 142.248.80.104:20292] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.248155 2026] [proxy:error] [pid 53359:tid 53495] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.248200 2026] [proxy_http:error] [pid 53359:tid 53495] [client 142.248.80.104:20212] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.248214 2026] [proxy:error] [pid 51003:tid 51133] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.248249 2026] [proxy_http:error] [pid 51003:tid 51133] [client 142.248.80.104:20110] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.248278 2026] [proxy:error] [pid 53359:tid 53537] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.248333 2026] [proxy:error] [pid 51003:tid 51164] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.248340 2026] [proxy_http:error] [pid 53359:tid 53537] [client 142.248.80.104:20234] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.248369 2026] [proxy_http:error] [pid 51003:tid 51164] [client 142.248.80.104:20118] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.248394 2026] [proxy:error] [pid 53359:tid 53610] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.248423 2026] [proxy_http:error] [pid 53359:tid 53610] [client 142.248.80.104:20172] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.248441 2026] [proxy:error] [pid 51003:tid 51184] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.248482 2026] [proxy_http:error] [pid 51003:tid 51184] [client 142.248.80.104:20146] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.248520 2026] [proxy:error] [pid 53359:tid 53558] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.248561 2026] [proxy_http:error] [pid 53359:tid 53558] [client 142.248.80.104:20206] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.248633 2026] [proxy:error] [pid 53359:tid 53620] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.248676 2026] [proxy_http:error] [pid 53359:tid 53620] [client 142.248.80.104:20122] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.248844 2026] [proxy:error] [pid 51003:tid 51164] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.248865 2026] [proxy_http:error] [pid 51003:tid 51164] [client 142.248.80.104:20118] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.248934 2026] [proxy:error] [pid 53359:tid 53549] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.248934 2026] [proxy:error] [pid 51003:tid 51145] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.248975 2026] [proxy_http:error] [pid 53359:tid 53549] [client 142.248.80.104:20160] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.248975 2026] [proxy_http:error] [pid 51003:tid 51145] [client 142.248.80.104:20154] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.249025 2026] [proxy:error] [pid 51003:tid 51133] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.249026 2026] [proxy:error] [pid 53359:tid 53537] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.249050 2026] [proxy_http:error] [pid 51003:tid 51133] [client 142.248.80.104:20110] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.249056 2026] [proxy_http:error] [pid 53359:tid 53537] [client 142.248.80.104:20234] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.249091 2026] [proxy:error] [pid 53359:tid 53610] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.249104 2026] [proxy:error] [pid 51003:tid 51135] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.249116 2026] [proxy_http:error] [pid 53359:tid 53610] [client 142.248.80.104:20172] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.249137 2026] [proxy_http:error] [pid 51003:tid 51135] [client 142.248.80.104:20134] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.249164 2026] [proxy:error] [pid 53359:tid 53558] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.249174 2026] [proxy:error] [pid 51003:tid 51184] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.249189 2026] [proxy_http:error] [pid 53359:tid 53558] [client 142.248.80.104:20206] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.249201 2026] [proxy_http:error] [pid 51003:tid 51184] [client 142.248.80.104:20146] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.249405 2026] [proxy:error] [pid 53359:tid 53620] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.249440 2026] [proxy_http:error] [pid 53359:tid 53620] [client 142.248.80.104:20122] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.249633 2026] [proxy:error] [pid 53359:tid 53549] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.249633 2026] [proxy:error] [pid 51003:tid 51145] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.249659 2026] [proxy_http:error] [pid 53359:tid 53549] [client 142.248.80.104:20160] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.249659 2026] [proxy_http:error] [pid 51003:tid 51145] [client 142.248.80.104:20154] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.249702 2026] [proxy:error] [pid 51003:tid 51135] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.249726 2026] [proxy_http:error] [pid 51003:tid 51135] [client 142.248.80.104:20134] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.390222 2026] [security2:error] [pid 51003:tid 51256] [client 103.125.146.34:38199] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/home.php"] [unique_id "ajCyncpsKyvb75pkSvaZ8QAAAgo"]
[Mon Jun 15 20:19:09.442461 2026] [proxy:error] [pid 51003:tid 51220] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.442461 2026] [proxy:error] [pid 53359:tid 53563] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.442538 2026] [proxy_http:error] [pid 51003:tid 51220] [client 142.248.80.104:19886] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.442540 2026] [proxy_http:error] [pid 53359:tid 53563] [client 142.248.80.104:19884] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.442615 2026] [proxy:error] [pid 53359:tid 53518] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.442655 2026] [proxy:error] [pid 51003:tid 51225] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.442665 2026] [proxy_http:error] [pid 53359:tid 53518] [client 142.248.80.104:19868] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.442705 2026] [proxy_http:error] [pid 51003:tid 51225] [client 142.248.80.104:19840] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.442760 2026] [security2:error] [pid 53359:tid 53521] [client 142.248.80.104:19756] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.convertease.us"] [uri "/___proxy_subdomain_cpcontacts/server/.env"] [unique_id "ajCynfC2Xs1VMQlhsga4OQAAAi4"]
[Mon Jun 15 20:19:09.442853 2026] [proxy:error] [pid 51003:tid 51148] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.442902 2026] [proxy_http:error] [pid 51003:tid 51148] [client 142.248.80.104:19854] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.442951 2026] [proxy:error] [pid 53359:tid 53536] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.443000 2026] [proxy_http:error] [pid 53359:tid 53536] [client 142.248.80.104:19784] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.443073 2026] [proxy:error] [pid 53359:tid 53561] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.443123 2026] [proxy_http:error] [pid 53359:tid 53561] [client 142.248.80.104:19808] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.443187 2026] [proxy:error] [pid 53359:tid 53563] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.443210 2026] [security2:error] [pid 51003:tid 51214] [client 142.248.80.104:19746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.convertease.us"] [uri "/___proxy_subdomain_cpcontacts/src/.env"] [unique_id "ajCyncpsKyvb75pkSvaZ-QAAAeA"]
[Mon Jun 15 20:19:09.443217 2026] [proxy:error] [pid 51003:tid 51220] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.443223 2026] [proxy_http:error] [pid 53359:tid 53563] [client 142.248.80.104:19884] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.443251 2026] [proxy_http:error] [pid 51003:tid 51220] [client 142.248.80.104:19886] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.443360 2026] [proxy:error] [pid 51003:tid 51250] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.443379 2026] [proxy:error] [pid 53359:tid 53518] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.443411 2026] [proxy_http:error] [pid 51003:tid 51250] [client 142.248.80.104:19800] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.443416 2026] [proxy_http:error] [pid 53359:tid 53518] [client 142.248.80.104:19868] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.443583 2026] [security2:error] [pid 53359:tid 53580] [client 142.248.80.104:19726] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.convertease.us"] [uri "/___proxy_subdomain_cpcontacts/backend/.env"] [unique_id "ajCynfC2Xs1VMQlhsga4OgAAAmk"]
[Mon Jun 15 20:19:09.443587 2026] [proxy:error] [pid 51003:tid 51148] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.443621 2026] [proxy_http:error] [pid 51003:tid 51148] [client 142.248.80.104:19854] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.443686 2026] [proxy:error] [pid 53359:tid 53536] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.443721 2026] [proxy_http:error] [pid 53359:tid 53536] [client 142.248.80.104:19784] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.443814 2026] [proxy:error] [pid 53359:tid 53561] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.443850 2026] [proxy_http:error] [pid 53359:tid 53561] [client 142.248.80.104:19808] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.443903 2026] [proxy:error] [pid 51003:tid 51225] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.443930 2026] [proxy_http:error] [pid 51003:tid 51225] [client 142.248.80.104:19840] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.444116 2026] [proxy:error] [pid 51003:tid 51250] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.444145 2026] [proxy_http:error] [pid 51003:tid 51250] [client 142.248.80.104:19800] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.444984 2026] [security2:error] [pid 53359:tid 53507] [client 142.248.80.104:19684] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcontacts.convertease.us"] [uri "/___proxy_subdomain_cpcontacts/.env.old"] [unique_id "ajCynfC2Xs1VMQlhsga4PAAAAiA"]
[Mon Jun 15 20:19:09.445263 2026] [proxy:error] [pid 53359:tid 53568] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.445307 2026] [proxy_http:error] [pid 53359:tid 53568] [client 142.248.80.104:19822] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.445333 2026] [proxy:error] [pid 51003:tid 51240] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.445375 2026] [proxy_http:error] [pid 51003:tid 51240] [client 142.248.80.104:19830] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.445428 2026] [security2:error] [pid 53359:tid 53590] [client 142.248.80.104:19646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcontacts.convertease.us"] [uri "/___proxy_subdomain_cpcontacts/.env.backup"] [unique_id "ajCynfC2Xs1VMQlhsga4PQAAAnM"]
[Mon Jun 15 20:19:09.445910 2026] [proxy:error] [pid 53359:tid 53606] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.445960 2026] [proxy_http:error] [pid 53359:tid 53606] [client 142.248.80.104:19676] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.445981 2026] [proxy:error] [pid 51003:tid 51240] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.446005 2026] [proxy_http:error] [pid 51003:tid 51240] [client 142.248.80.104:19830] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.446029 2026] [proxy:error] [pid 53359:tid 53568] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.446079 2026] [proxy_http:error] [pid 53359:tid 53568] [client 142.248.80.104:19822] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.446078 2026] [proxy:error] [pid 51003:tid 51152] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.446124 2026] [proxy_http:error] [pid 51003:tid 51152] [client 142.248.80.104:19786] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.446203 2026] [proxy:error] [pid 51003:tid 51168] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.446203 2026] [proxy:error] [pid 53359:tid 53547] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.446247 2026] [proxy_http:error] [pid 51003:tid 51168] [client 142.248.80.104:19878] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.446247 2026] [proxy_http:error] [pid 53359:tid 53547] [client 142.248.80.104:19696] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.446478 2026] [security2:error] [pid 53359:tid 53529] [client 142.248.80.104:19626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.convertease.us"] [uri "/___proxy_subdomain_cpcontacts/.env"] [unique_id "ajCynfC2Xs1VMQlhsga4QAAAAjY"]
[Mon Jun 15 20:19:09.446535 2026] [security2:error] [pid 51003:tid 51242] [client 142.248.80.104:19776] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.convertease.us"] [uri "/___proxy_subdomain_cpcontacts/public/.env"] [unique_id "ajCyncpsKyvb75pkSvaZ_QAAAfw"]
[Mon Jun 15 20:19:09.446632 2026] [proxy:error] [pid 53359:tid 53606] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.446665 2026] [proxy_http:error] [pid 53359:tid 53606] [client 142.248.80.104:19676] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.446823 2026] [proxy:error] [pid 51003:tid 51152] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.446860 2026] [proxy_http:error] [pid 51003:tid 51152] [client 142.248.80.104:19786] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.446919 2026] [proxy:error] [pid 53359:tid 53547] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.446919 2026] [proxy:error] [pid 51003:tid 51168] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.446945 2026] [proxy_http:error] [pid 51003:tid 51168] [client 142.248.80.104:19878] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.446945 2026] [proxy_http:error] [pid 53359:tid 53547] [client 142.248.80.104:19696] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.447060 2026] [security2:error] [pid 51003:tid 51252] [client 142.248.80.104:19764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.convertease.us"] [uri "/___proxy_subdomain_cpcontacts/web/.env"] [unique_id "ajCyncpsKyvb75pkSvaZ_wAAAgY"]
[Mon Jun 15 20:19:09.447304 2026] [security2:error] [pid 51003:tid 51182] [client 142.248.80.104:19720] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.convertease.us"] [uri "/___proxy_subdomain_cpcontacts/api/.env"] [unique_id "ajCyncpsKyvb75pkSvaaAAAAAcA"]
[Mon Jun 15 20:19:09.447349 2026] [proxy:error] [pid 51003:tid 51260] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.447388 2026] [proxy_http:error] [pid 51003:tid 51260] [client 142.248.80.104:19838] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.447445 2026] [proxy:error] [pid 53359:tid 53516] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.447482 2026] [proxy_http:error] [pid 53359:tid 53516] [client 142.248.80.104:19674] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.447781 2026] [security2:error] [pid 51003:tid 51141] [client 142.248.80.104:19736] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.convertease.us"] [uri "/___proxy_subdomain_cpcontacts/laravel/.env"] [unique_id "ajCyncpsKyvb75pkSvaaAQAAAZc"]
[Mon Jun 15 20:19:09.447980 2026] [proxy:error] [pid 51003:tid 51260] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.447981 2026] [proxy:error] [pid 53359:tid 53599] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.448004 2026] [proxy_http:error] [pid 51003:tid 51260] [client 142.248.80.104:19838] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.448021 2026] [security2:error] [pid 51003:tid 51190] [client 142.248.80.104:19704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.convertease.us"] [uri "/___proxy_subdomain_cpcontacts/app/.env"] [unique_id "ajCyncpsKyvb75pkSvaaAgAAAcg"]
[Mon Jun 15 20:19:09.448025 2026] [proxy_http:error] [pid 53359:tid 53599] [client 142.248.80.104:19658] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.448103 2026] [proxy:error] [pid 53359:tid 53598] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.448147 2026] [proxy_http:error] [pid 53359:tid 53598] [client 142.248.80.104:19628] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.448197 2026] [proxy:error] [pid 53359:tid 53516] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.448224 2026] [proxy_http:error] [pid 53359:tid 53516] [client 142.248.80.104:19674] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.448699 2026] [proxy:error] [pid 53359:tid 53598] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.448728 2026] [proxy_http:error] [pid 53359:tid 53598] [client 142.248.80.104:19628] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.448794 2026] [proxy:error] [pid 53359:tid 53599] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.448826 2026] [proxy_http:error] [pid 53359:tid 53599] [client 142.248.80.104:19658] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.448881 2026] [security2:error] [pid 51003:tid 51207] [client 142.248.80.104:19638] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcontacts.convertease.us"] [uri "/___proxy_subdomain_cpcontacts/.env.bak"] [unique_id "ajCyncpsKyvb75pkSvaaAwAAAdk"]
[Mon Jun 15 20:19:09.448885 2026] [proxy:error] [pid 53359:tid 53518] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.448926 2026] [proxy_http:error] [pid 53359:tid 53518] [client 142.248.80.104:19630] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.449084 2026] [proxy:error] [pid 51003:tid 51179] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.449123 2026] [proxy_http:error] [pid 51003:tid 51179] [client 142.248.80.104:19852] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.449304 2026] [proxy:error] [pid 51003:tid 51238] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.449353 2026] [proxy_http:error] [pid 51003:tid 51238] [client 142.248.80.104:20186] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.449463 2026] [proxy:error] [pid 53359:tid 53518] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.449484 2026] [proxy_http:error] [pid 53359:tid 53518] [client 142.248.80.104:19630] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.449569 2026] [proxy:error] [pid 51003:tid 51179] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.449591 2026] [proxy_http:error] [pid 51003:tid 51179] [client 142.248.80.104:19852] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.449787 2026] [proxy:error] [pid 51003:tid 51238] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:09.449809 2026] [proxy_http:error] [pid 51003:tid 51238] [client 142.248.80.104:20186] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:09.791725 2026] [security2:error] [pid 53359:tid 53553] [client 103.125.146.64:30175] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/block-patterns/"] [unique_id "ajCynfC2Xs1VMQlhsga4TQAAAk4"]
[Mon Jun 15 20:19:10.163743 2026] [security2:error] [pid 51003:tid 51011] [remote 89.58.31.106:41260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.31.58.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cricketrings.com"] [uri "/wp-login.php"] [unique_id "ajCynspsKyvb75pkSvaaGgACAgc"]
[Mon Jun 15 20:19:10.380830 2026] [security2:error] [pid 51003:tid 51006] [remote 89.58.31.106:41260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.31.58.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cricketrings.com"] [uri "/wp-login.php"] [unique_id "ajCynspsKyvb75pkSvaaHgABzAI"], referer: https://cricketrings.com/wp-login.php
[Mon Jun 15 20:19:10.414307 2026] [security2:error] [pid 53359:tid 53612] [client 103.125.146.57:50667] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/css/dist/edit-site/"] [unique_id "ajCynvC2Xs1VMQlhsga4ZAAAAok"]
[Mon Jun 15 20:19:10.581117 2026] [security2:error] [pid 53359:tid 53621] [client 181.192.93.194:38065] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "newsymcon.symcon.in"] [uri "/xmlrpc.php"] [unique_id "ajCynvC2Xs1VMQlhsga4aAAAApI"]
[Mon Jun 15 20:19:10.667981 2026] [security2:error] [pid 53359:tid 53587] [client 139.99.122.191:56000] ModSecurity: Access denied with code 406 (phase 1). Pattern match "xmlrpc\\\\.php" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "73"] [id "392331"] [rev "3"] [msg "Atomicorp.com WAF Rules: xmlrpc DOS attack"] [severity "CRITICAL"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCynvC2Xs1VMQlhsga4fQAAAnA"]
[Mon Jun 15 20:19:10.668065 2026] [security2:error] [pid 53359:tid 53587] [client 139.99.122.191:56000] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCynvC2Xs1VMQlhsga4fQAAAnA"]
[Mon Jun 15 20:19:10.759564 2026] [proxy:error] [pid 51003:tid 51220] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:10.759651 2026] [proxy_http:error] [pid 51003:tid 51220] [client 142.248.80.104:20328] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:10.759740 2026] [proxy:error] [pid 51003:tid 51214] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:10.759803 2026] [proxy_http:error] [pid 51003:tid 51214] [client 142.248.80.104:20334] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:10.759897 2026] [proxy:error] [pid 51003:tid 51256] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:10.759951 2026] [proxy_http:error] [pid 51003:tid 51256] [client 142.248.80.104:20314] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:10.760186 2026] [proxy:error] [pid 51003:tid 51220] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:10.760230 2026] [proxy_http:error] [pid 51003:tid 51220] [client 142.248.80.104:20328] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:10.760446 2026] [proxy:error] [pid 51003:tid 51214] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:10.760476 2026] [proxy_http:error] [pid 51003:tid 51214] [client 142.248.80.104:20334] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:10.760656 2026] [proxy:error] [pid 51003:tid 51256] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:10.760692 2026] [proxy_http:error] [pid 51003:tid 51256] [client 142.248.80.104:20314] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:10.797047 2026] [security2:error] [pid 53359:tid 53498] [client 103.125.146.41:31433] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/css/dist/edit-widgets/"] [unique_id "ajCynvC2Xs1VMQlhsga4igAAAhc"]
[Mon Jun 15 20:19:10.923493 2026] [security2:error] [pid 53359:tid 53556] [client 49.37.157.202:59473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "desidelightmp.com"] [uri "/xmlrpc.php"] [unique_id "ajCynvC2Xs1VMQlhsga4jAAAAlE"]
[Mon Jun 15 20:19:10.923609 2026] [security2:error] [pid 53359:tid 53556] [client 49.37.157.202:59473] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "desidelightmp.com"] [uri "/xmlrpc.php"] [unique_id "ajCynvC2Xs1VMQlhsga4jAAAAlE"]
[Mon Jun 15 20:19:11.061108 2026] [security2:error] [pid 53359:tid 53602] [client 57.141.14.12:42226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCynvC2Xs1VMQlhsga4jwACfzU"]
[Mon Jun 15 20:19:11.163169 2026] [security2:error] [pid 53359:tid 53603] [client 110.235.130.91:60199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.130.235.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nxtal.com"] [uri "/xmlrpc.php"] [unique_id "ajCyn_C2Xs1VMQlhsga4lwAAAoA"]
[Mon Jun 15 20:19:11.163283 2026] [security2:error] [pid 53359:tid 53603] [client 110.235.130.91:60199] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nxtal.com"] [uri "/xmlrpc.php"] [unique_id "ajCyn_C2Xs1VMQlhsga4lwAAAoA"]
[Mon Jun 15 20:19:11.223817 2026] [security2:error] [pid 53359:tid 53533] [client 103.125.146.70:35939] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/css/config.php"] [unique_id "ajCyn_C2Xs1VMQlhsga4nAAAAjo"]
[Mon Jun 15 20:19:11.238426 2026] [security2:error] [pid 53359:tid 53446] [remote 209.74.93.184:59280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.93.74.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "teacherrk.com"] [uri "/wp-login.php"] [unique_id "ajCyn_C2Xs1VMQlhsga4nQACOVA"]
[Mon Jun 15 20:19:11.379049 2026] [security2:error] [pid 53359:tid 53535] [client 192.140.64.94:29927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.64.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCyn_C2Xs1VMQlhsga4oQAAAjw"]
[Mon Jun 15 20:19:11.379154 2026] [security2:error] [pid 53359:tid 53535] [client 192.140.64.94:29927] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCyn_C2Xs1VMQlhsga4oQAAAjw"]
[Mon Jun 15 20:19:11.472804 2026] [security2:error] [pid 53359:tid 53565] [client 43.173.180.204:59636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.180.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mahavirgems.in"] [uri "/index.php"] [unique_id "ajCyn_C2Xs1VMQlhsga4owAAAlo"], referer: https://www.mahavirgems.in/freshwater-cultivated-pearl-3-Carat
[Mon Jun 15 20:19:11.639230 2026] [security2:error] [pid 51003:tid 51212] [client 103.125.146.32:41411] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/wp-config.php"] [unique_id "ajCyn8psKyvb75pkSvaaRQAAAd4"]
[Mon Jun 15 20:19:11.986402 2026] [autoindex:error] [pid 51003:tid 51175] [client 43.133.42.227:49768] AH01276: Cannot serve directory /home2/lrfcoxmy/public_html/oaklivinfra/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:19:12.022669 2026] [security2:error] [pid 53359:tid 53576] [client 103.125.146.57:43075] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/customize/"] [unique_id "ajCyoPC2Xs1VMQlhsga4uQAAAmU"]
[Mon Jun 15 20:19:12.323773 2026] [security2:error] [pid 53359:tid 53605] [client 47.79.201.224:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "societytodaynews.com"] [uri "/index.php"] [unique_id "ajCyoPC2Xs1VMQlhsga4vAAAAoI"], referer: https://www.google.com/
[Mon Jun 15 20:19:12.384771 2026] [security2:error] [pid 51003:tid 51133] [client 57.141.14.100:23605] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyoMpsKyvb75pkSvaaXwABj0Y"]
[Mon Jun 15 20:19:12.433271 2026] [security2:error] [pid 53359:tid 53523] [client 103.125.146.42:37403] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/css/dist/admin.php"] [unique_id "ajCyoPC2Xs1VMQlhsga4yQAAAjA"]
[Mon Jun 15 20:19:12.743090 2026] [autoindex:error] [pid 53359:tid 53500] [client 192.175.111.247:49303] AH01276: Cannot serve directory /home1/rugqjjmy/public_html/jpmorganchasecorp/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:19:12.989399 2026] [security2:error] [pid 53359:tid 53601] [client 57.141.14.79:21396] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fifthestate.agency"] [uri "/index.php"] [unique_id "ajCyoPC2Xs1VMQlhsga41gACfmo"]
[Mon Jun 15 20:19:13.025155 2026] [security2:error] [pid 53359:tid 53514] [client 103.125.146.71:52323] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-admin/css/colors/ectoplasm/min.php"] [unique_id "ajCyofC2Xs1VMQlhsga42gAAAic"]
[Mon Jun 15 20:19:13.064470 2026] [security2:error] [pid 53359:tid 53534] [client 186.84.88.205:17219] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "wantpg.com"] [uri "/public/index.php/pg-in-jechtingen-591479"] [unique_id "ajCyofC2Xs1VMQlhsga43AAAAjs"]
[Mon Jun 15 20:19:13.445068 2026] [security2:error] [pid 53359:tid 53604] [client 103.125.146.71:64395] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wolf.php"] [unique_id "ajCyofC2Xs1VMQlhsga46gAAAoE"]
[Mon Jun 15 20:19:13.623023 2026] [security2:error] [pid 53359:tid 53418] [remote 209.74.93.184:59280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.93.74.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "teacherrk.com"] [uri "/wp-login.php"] [unique_id "ajCyofC2Xs1VMQlhsga47QACVTQ"], referer: https://teacherrk.com/wp-login.php
[Mon Jun 15 20:19:13.760814 2026] [proxy:error] [pid 51003:tid 51215] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:13.760882 2026] [proxy_http:error] [pid 51003:tid 51215] [client 142.248.80.104:19746] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:13.761886 2026] [proxy:error] [pid 51003:tid 51215] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:13.761930 2026] [proxy_http:error] [pid 51003:tid 51215] [client 142.248.80.104:19746] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:13.826415 2026] [security2:error] [pid 53359:tid 53525] [client 57.141.14.59:63323] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyofC2Xs1VMQlhsga47gACMlM"]
[Mon Jun 15 20:19:13.834898 2026] [security2:error] [pid 53359:tid 53497] [client 103.125.146.70:52333] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/security.php"] [unique_id "ajCyofC2Xs1VMQlhsga48gAAAhY"]
[Mon Jun 15 20:19:13.928478 2026] [security2:error] [pid 53359:tid 53521] [client 139.99.122.191:56118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.122.99.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srinivasgorthyandco.com"] [uri "/wp-login.php"] [unique_id "ajCyofC2Xs1VMQlhsga4-QAAAi4"]
[Mon Jun 15 20:19:14.043813 2026] [security2:error] [pid 53359:tid 53489] [remote 216.73.217.151:44950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wilsonoverseas.com"] [uri "/"] [unique_id "ajCyovC2Xs1VMQlhsga4-wACH3s"]
[Mon Jun 15 20:19:14.158641 2026] [security2:error] [pid 53359:tid 53593] [client 139.99.122.191:56188] ModSecurity: Access denied with code 406 (phase 1). Pattern match "xmlrpc\\\\.php" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "73"] [id "392331"] [rev "3"] [msg "Atomicorp.com WAF Rules: xmlrpc DOS attack"] [severity "CRITICAL"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCyovC2Xs1VMQlhsga4_wAAAnY"]
[Mon Jun 15 20:19:14.158769 2026] [security2:error] [pid 53359:tid 53593] [client 139.99.122.191:56188] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCyovC2Xs1VMQlhsga4_wAAAnY"]
[Mon Jun 15 20:19:14.190657 2026] [security2:error] [pid 53359:tid 53606] [client 43.173.173.253:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCyofC2Xs1VMQlhsga48wACgy0"]
[Mon Jun 15 20:19:14.192848 2026] [proxy:error] [pid 51003:tid 51208] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:14.192943 2026] [proxy_http:error] [pid 51003:tid 51208] [client 143.244.57.82:54422] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:14.194766 2026] [proxy:error] [pid 51003:tid 51208] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:14.194834 2026] [proxy_http:error] [pid 51003:tid 51208] [client 143.244.57.82:54422] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:14.203392 2026] [security2:error] [pid 53359:tid 53515] [client 103.125.146.75:25629] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/tager.php"] [unique_id "ajCyovC2Xs1VMQlhsga5AQAAAig"]
[Mon Jun 15 20:19:14.487626 2026] [proxy:error] [pid 51003:tid 51145] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:14.487724 2026] [proxy_http:error] [pid 51003:tid 51145] [client 143.244.57.82:54436] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:14.488697 2026] [proxy:error] [pid 51003:tid 51145] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:14.488758 2026] [proxy_http:error] [pid 51003:tid 51145] [client 143.244.57.82:54436] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:14.606264 2026] [security2:error] [pid 53359:tid 53580] [client 139.99.122.191:56266] ModSecurity: Access denied with code 406 (phase 1). Pattern match "xmlrpc\\\\.php" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "73"] [id "392331"] [rev "3"] [msg "Atomicorp.com WAF Rules: xmlrpc DOS attack"] [severity "CRITICAL"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCyovC2Xs1VMQlhsga5FAAAAmk"]
[Mon Jun 15 20:19:14.606404 2026] [security2:error] [pid 53359:tid 53580] [client 139.99.122.191:56266] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCyovC2Xs1VMQlhsga5FAAAAmk"]
[Mon Jun 15 20:19:14.774645 2026] [security2:error] [pid 51003:tid 51153] [client 143.244.57.82:54438] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jalotafinserv.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ajCyospsKyvb75pkSvaaoAAAAaM"]
[Mon Jun 15 20:19:14.962726 2026] [security2:error] [pid 53359:tid 53549] [client 139.99.122.191:56386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.122.99.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srinivasgorthyandco.com"] [uri "/wp-login.php"] [unique_id "ajCyovC2Xs1VMQlhsga5LAAAAko"]
[Mon Jun 15 20:19:14.968798 2026] [security2:error] [pid 53359:tid 53495] [client 47.79.207.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "db.geeksinsight.com"] [uri "/index.php"] [unique_id "ajCyovC2Xs1VMQlhsga5KgAAAhQ"], referer: https://www.google.com/
[Mon Jun 15 20:19:15.083172 2026] [security2:error] [pid 51003:tid 51137] [client 143.244.57.82:54448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.jalotafinserv.com"] [uri "/xmlrpc.php"] [unique_id "ajCyo8psKyvb75pkSvaapgAAAZM"]
[Mon Jun 15 20:19:15.357509 2026] [proxy:error] [pid 53359:tid 53579] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:15.357564 2026] [proxy_http:error] [pid 53359:tid 53579] [client 143.244.57.82:54454] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:15.358263 2026] [proxy:error] [pid 53359:tid 53579] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:15.358292 2026] [proxy_http:error] [pid 53359:tid 53579] [client 143.244.57.82:54454] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:15.391434 2026] [security2:error] [pid 51003:tid 51151] [client 57.141.14.48:33249] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyo8psKyvb75pkSvaaqwABoT8"]
[Mon Jun 15 20:19:15.503622 2026] [security2:error] [pid 51003:tid 51005] [remote 198.38.94.14:49632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.94.38.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "procrastinatingworker.com"] [uri "/wp-login.php"] [unique_id "ajCyo8psKyvb75pkSvaasQAB4QE"]
[Mon Jun 15 20:19:15.533837 2026] [security2:error] [pid 51003:tid 51078] [remote 57.141.14.76:38613] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fifthestate.agency"] [uri "/index.php"] [unique_id "ajCyo8psKyvb75pkSvaarAABr0o"]
[Mon Jun 15 20:19:15.662157 2026] [security2:error] [pid 53359:tid 53508] [client 143.244.57.82:54458] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jalotafinserv.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ajCyo_C2Xs1VMQlhsga5SgAAAiE"]
[Mon Jun 15 20:19:15.978484 2026] [security2:error] [pid 53359:tid 53582] [client 143.244.57.82:54464] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jalotafinserv.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ajCyo_C2Xs1VMQlhsga5WgAAAms"]
[Mon Jun 15 20:19:15.992086 2026] [security2:error] [pid 51003:tid 51146] [client 47.79.200.150:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "societytodaynews.com"] [uri "/index.php"] [unique_id "ajCyo8psKyvb75pkSvaavQAAAZw"], referer: https://www.google.com/
[Mon Jun 15 20:19:16.132634 2026] [security2:error] [pid 53359:tid 53587] [client 66.249.79.226:49421] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.majividyarthikes.com"] [uri "/index.php"] [unique_id "ajCyo_C2Xs1VMQlhsga5UgAAAnA"]
[Mon Jun 15 20:19:16.263075 2026] [security2:error] [pid 53359:tid 53609] [client 143.244.57.82:54468] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jalotafinserv.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ajCypPC2Xs1VMQlhsga5aAAAAoY"]
[Mon Jun 15 20:19:16.322962 2026] [security2:error] [pid 51003:tid 51210] [client 65.111.30.222:20217] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.procrastinatingworker.imcorp.in"] [uri "/index.php"] [unique_id "ajCypMpsKyvb75pkSvaayAAAAdw"]
[Mon Jun 15 20:19:16.368023 2026] [security2:error] [pid 51003:tid 51209] [client 139.99.122.191:56450] ModSecurity: Access denied with code 406 (phase 1). Pattern match "xmlrpc\\\\.php" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "73"] [id "392331"] [rev "3"] [msg "Atomicorp.com WAF Rules: xmlrpc DOS attack"] [severity "CRITICAL"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCypMpsKyvb75pkSvaazgAAAds"]
[Mon Jun 15 20:19:16.368173 2026] [security2:error] [pid 51003:tid 51209] [client 139.99.122.191:56450] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCypMpsKyvb75pkSvaazgAAAds"]
[Mon Jun 15 20:19:16.556428 2026] [security2:error] [pid 51003:tid 51236] [client 143.244.57.82:54484] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jalotafinserv.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "ajCypMpsKyvb75pkSvaa1wAAAfY"]
[Mon Jun 15 20:19:16.607455 2026] [security2:error] [pid 51003:tid 51220] [client 139.99.122.191:56452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.122.99.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srinivasgorthyandco.com"] [uri "/wp-login.php"] [unique_id "ajCypMpsKyvb75pkSvaa2gAAAeY"]
[Mon Jun 15 20:19:16.849721 2026] [security2:error] [pid 51003:tid 51178] [client 143.244.57.82:54492] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jalotafinserv.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ajCypMpsKyvb75pkSvaa5gAAAbw"]
[Mon Jun 15 20:19:16.861810 2026] [security2:error] [pid 53359:tid 53433] [remote 185.31.65.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.65.31.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fashionsfever.com"] [uri "/wp-login.php"] [unique_id "ajCypPC2Xs1VMQlhsga5gQACVEM"]
[Mon Jun 15 20:19:16.923823 2026] [security2:error] [pid 51003:tid 51248] [client 139.99.122.191:56612] ModSecurity: Access denied with code 406 (phase 1). Pattern match "xmlrpc\\\\.php" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "73"] [id "392331"] [rev "3"] [msg "Atomicorp.com WAF Rules: xmlrpc DOS attack"] [severity "CRITICAL"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCypMpsKyvb75pkSvaa6wAAAgI"]
[Mon Jun 15 20:19:16.923980 2026] [security2:error] [pid 51003:tid 51248] [client 139.99.122.191:56612] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCypMpsKyvb75pkSvaa6wAAAgI"]
[Mon Jun 15 20:19:16.932578 2026] [security2:error] [pid 53359:tid 53518] [client 57.141.14.11:47159] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCypPC2Xs1VMQlhsga5fgACKxM"]
[Mon Jun 15 20:19:16.944033 2026] [security2:error] [pid 53359:tid 53482] [remote 43.173.173.74:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCyo_C2Xs1VMQlhsga5TAACdXQ"], referer: https://mywordsnthoughts.com/bread-rolls-fried/
[Mon Jun 15 20:19:16.957912 2026] [security2:error] [pid 51003:tid 51179] [client 139.99.122.191:56620] ModSecurity: Access denied with code 406 (phase 1). Pattern match "xmlrpc\\\\.php" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "73"] [id "392331"] [rev "3"] [msg "Atomicorp.com WAF Rules: xmlrpc DOS attack"] [severity "CRITICAL"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCypMpsKyvb75pkSvaa7gAAAb0"]
[Mon Jun 15 20:19:16.958078 2026] [security2:error] [pid 51003:tid 51179] [client 139.99.122.191:56620] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCypMpsKyvb75pkSvaa7gAAAb0"]
[Mon Jun 15 20:19:16.994476 2026] [security2:error] [pid 53359:tid 53467] [remote 43.173.174.172:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCyo_C2Xs1VMQlhsga5TQACSGU"], referer: https://mywordsnthoughts.com/bread-rolls-fried/
[Mon Jun 15 20:19:17.133520 2026] [security2:error] [pid 51003:tid 51211] [client 143.244.57.82:54508] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jalotafinserv.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "ajCypcpsKyvb75pkSvaa-AAAAd0"]
[Mon Jun 15 20:19:17.193555 2026] [security2:error] [pid 53359:tid 53568] [client 181.192.93.194:38870] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "newsymcon.symcon.in"] [uri "/xmlrpc.php"] [unique_id "ajCypfC2Xs1VMQlhsga5kgAAAl0"]
[Mon Jun 15 20:19:17.209402 2026] [security2:error] [pid 53359:tid 53586] [client 139.99.122.191:56658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.122.99.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srinivasgorthyandco.com"] [uri "/wp-login.php"] [unique_id "ajCypfC2Xs1VMQlhsga5lAAAAm8"]
[Mon Jun 15 20:19:17.230108 2026] [security2:error] [pid 53359:tid 53564] [client 43.172.198.156:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "itdeed.com"] [uri "/demomahayogini/product/\\xf0\\x9f\\x95\\x89\\xef\\xb8\\x8f-arisht-gun-dosh-nivaran-puja-and-homam"] [unique_id "ajCypfC2Xs1VMQlhsga5lQAAAlk"]
[Mon Jun 15 20:19:17.291789 2026] [security2:error] [pid 51003:tid 51155] [client 43.173.177.76:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "itdeed.com"] [uri "/demomahayogini/product-tag/vishnu-sahasranama-chanting"] [unique_id "ajCypcpsKyvb75pkSvabAAAAAaU"]
[Mon Jun 15 20:19:17.337897 2026] [security2:error] [pid 53359:tid 53479] [remote 185.31.65.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.65.31.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fashionsfever.com"] [uri "/wp-login.php"] [unique_id "ajCypfC2Xs1VMQlhsga5lwACanE"], referer: https://fashionsfever.com/wp-login.php
[Mon Jun 15 20:19:17.393596 2026] [security2:error] [pid 53359:tid 53512] [client 2804:1ed8:117d:800:84da:473a:a9aa:1193:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kthemani.com"] [uri "/index.php"] [unique_id "ajCyo_C2Xs1VMQlhsga5NwACJWg"]
[Mon Jun 15 20:19:17.437089 2026] [security2:error] [pid 53359:tid 53519] [client 143.244.57.82:54524] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jalotafinserv.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "ajCypfC2Xs1VMQlhsga5mAAAAiw"]
[Mon Jun 15 20:19:17.587707 2026] [security2:error] [pid 53359:tid 53517] [client 31.219.209.201:14474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.209.219.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCypfC2Xs1VMQlhsga5ngAAAio"]
[Mon Jun 15 20:19:17.587846 2026] [security2:error] [pid 53359:tid 53517] [client 31.219.209.201:14474] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCypfC2Xs1VMQlhsga5ngAAAio"]
[Mon Jun 15 20:19:17.718006 2026] [security2:error] [pid 53359:tid 53574] [client 143.244.57.82:54526] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jalotafinserv.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ajCypfC2Xs1VMQlhsga5pQAAAmM"]
[Mon Jun 15 20:19:17.738540 2026] [security2:error] [pid 51003:tid 51181] [client 43.172.196.227:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCyo8psKyvb75pkSvaawQABv2E"], referer: https://mywordsnthoughts.com/stuffed-pomfret-stuffed-avoli/
[Mon Jun 15 20:19:17.770355 2026] [security2:error] [pid 51003:tid 51227] [client 43.173.182.88:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCyo8psKyvb75pkSvaavwAB7Qk"], referer: https://mywordsnthoughts.com/do-you-know-sushant-singh-rajput-was-more-successful-than-shah-rukh-khan-in-the-past-5-years/
[Mon Jun 15 20:19:17.775932 2026] [security2:error] [pid 53359:tid 53590] [client 43.173.181.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCyo_C2Xs1VMQlhsga5TgACczI"], referer: https://mywordsnthoughts.com/stuffed-pomfret-stuffed-avoli/
[Mon Jun 15 20:19:17.782093 2026] [security2:error] [pid 53359:tid 53507] [client 139.99.122.191:56764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.122.99.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srinivasgorthyandco.com"] [uri "/wp-login.php"] [unique_id "ajCypfC2Xs1VMQlhsga5pgAAAiA"]
[Mon Jun 15 20:19:17.814438 2026] [security2:error] [pid 53359:tid 53524] [client 139.99.122.191:56778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.122.99.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srinivasgorthyandco.com"] [uri "/wp-login.php"] [unique_id "ajCypfC2Xs1VMQlhsga5pwAAAjE"]
[Mon Jun 15 20:19:17.851305 2026] [security2:error] [pid 53359:tid 53566] [client 43.173.180.191:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCyo_C2Xs1VMQlhsga5UAACWw8"], referer: https://mywordsnthoughts.com/do-you-know-sushant-singh-rajput-was-more-successful-than-shah-rukh-khan-in-the-past-5-years/
[Mon Jun 15 20:19:17.986896 2026] [security2:error] [pid 53359:tid 53495] [client 143.244.57.82:54530] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jalotafinserv.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ajCypfC2Xs1VMQlhsga5rgAAAhQ"]
[Mon Jun 15 20:19:18.098809 2026] [security2:error] [pid 53359:tid 53558] [client 43.173.173.224:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCypPC2Xs1VMQlhsga5YgACUyY"], referer: https://mywordsnthoughts.com/hasrat-jaipuri-top-50-bollywood-classical-songs/
[Mon Jun 15 20:19:18.098891 2026] [security2:error] [pid 53359:tid 53538] [client 43.172.198.164:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCypPC2Xs1VMQlhsga5ZAACPxw"], referer: https://mywordsnthoughts.com/hasrat-jaipuri-top-50-bollywood-classical-songs/
[Mon Jun 15 20:19:18.184023 2026] [security2:error] [pid 53359:tid 53576] [client 43.173.177.156:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCypPC2Xs1VMQlhsga5cQACZW8"], referer: https://mywordsnthoughts.com/observe-these-phases-as-your-infant-grows/
[Mon Jun 15 20:19:18.184577 2026] [security2:error] [pid 53359:tid 53557] [client 43.172.194.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCypPC2Xs1VMQlhsga5cgACUkg"], referer: https://mywordsnthoughts.com/observe-these-phases-as-your-infant-grows/
[Mon Jun 15 20:19:18.262265 2026] [security2:error] [pid 53359:tid 53539] [client 143.244.57.82:54536] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jalotafinserv.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "ajCypvC2Xs1VMQlhsga5ugAAAkA"]
[Mon Jun 15 20:19:18.264335 2026] [security2:error] [pid 53359:tid 53620] [client 66.249.64.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCypPC2Xs1VMQlhsga5YwACkXI"]
[Mon Jun 15 20:19:18.305503 2026] [security2:error] [pid 51003:tid 51231] [client 57.141.14.106:27899] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCypspsKyvb75pkSvabFgAB8WA"]
[Mon Jun 15 20:19:18.510539 2026] [security2:error] [pid 53359:tid 53523] [client 162.214.80.21:36840] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "itdeed.com"] [uri "/demomahayogini/wp-cron.php"] [unique_id "ajCypvC2Xs1VMQlhsga5xQAAAjA"]
[Mon Jun 15 20:19:18.519808 2026] [security2:error] [pid 53359:tid 53537] [client 43.173.180.121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itdeed.com"] [uri "/demomahayogini/index.php"] [unique_id "ajCypfC2Xs1VMQlhsga5rwAAAj4"], referer: https://itdeed.com/demomahayogini/product/%f0%9f%95%89%ef%b8%8f-arisht-gun-dosh-nivaran-puja-and-homam
[Mon Jun 15 20:19:18.548897 2026] [security2:error] [pid 53359:tid 53517] [client 143.244.57.82:54542] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jalotafinserv.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "ajCypvC2Xs1VMQlhsga5yAAAAio"]
[Mon Jun 15 20:19:18.565516 2026] [security2:error] [pid 53359:tid 53602] [client 47.79.202.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "societytodaynews.com"] [uri "/index.php"] [unique_id "ajCypvC2Xs1VMQlhsga5uQAAAn8"], referer: https://www.google.com/
[Mon Jun 15 20:19:18.820859 2026] [security2:error] [pid 53359:tid 53562] [client 162.214.80.21:36842] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "itdeed.com"] [uri "/demomahayogini/wp-cron.php"] [unique_id "ajCypvC2Xs1VMQlhsga50gAAAlc"]
[Mon Jun 15 20:19:18.828513 2026] [security2:error] [pid 51003:tid 51204] [client 43.172.195.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itdeed.com"] [uri "/demomahayogini/index.php"] [unique_id "ajCypspsKyvb75pkSvabHgAAAdY"], referer: https://itdeed.com/demomahayogini/product-tag/vishnu-sahasranama-chanting
[Mon Jun 15 20:19:18.847738 2026] [security2:error] [pid 53359:tid 53536] [client 143.244.57.82:54554] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jalotafinserv.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ajCypvC2Xs1VMQlhsga51AAAAj0"]
[Mon Jun 15 20:19:19.158706 2026] [security2:error] [pid 51003:tid 51098] [remote 84.55.5.241:29719] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "rajunandkardeputycollector.blog"] [uri "/wp-content/plugins/updraftplus/readme.txt"] [unique_id "ajCyp8psKyvb75pkSvabKgAB9V4"], referer: https://rajunandkardeputycollector.blog/
[Mon Jun 15 20:19:19.162265 2026] [security2:error] [pid 53359:tid 53521] [client 143.244.57.82:54562] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jalotafinserv.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ajCyp_C2Xs1VMQlhsga54QAAAi4"]
[Mon Jun 15 20:19:19.445290 2026] [security2:error] [pid 53359:tid 53537] [client 143.244.57.82:54572] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jalotafinserv.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "ajCyp_C2Xs1VMQlhsga56gAAAj4"]
[Mon Jun 15 20:19:19.500893 2026] [security2:error] [pid 53359:tid 53594] [client 112.86.225.69:34890] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.diggysguide.com"] [uri "/pirates-2/jamalias-den"] [unique_id "ajCyp_C2Xs1VMQlhsga56wAAAnc"]
[Mon Jun 15 20:19:19.501000 2026] [security2:error] [pid 53359:tid 53594] [client 112.86.225.69:34890] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.diggysguide.com"] [uri "/pirates-2/jamalias-den"] [unique_id "ajCyp_C2Xs1VMQlhsga56wAAAnc"]
[Mon Jun 15 20:19:19.620093 2026] [security2:error] [pid 53359:tid 53619] [client 103.125.146.72:43411] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/RioX.php"] [unique_id "ajCyp_C2Xs1VMQlhsga57gAAApA"]
[Mon Jun 15 20:19:19.630972 2026] [security2:error] [pid 51003:tid 51116] [remote 43.173.178.53:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.178.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mywordsnthoughts.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ajCyp8psKyvb75pkSvabMQABsnA"], referer: https://mywordsnthoughts.com/hasrat-jaipuri-top-50-bollywood-classical-songs/
[Mon Jun 15 20:19:19.724972 2026] [security2:error] [pid 53359:tid 53548] [client 57.141.14.73:41510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fifthestate.agency"] [uri "/index.php"] [unique_id "ajCyp_C2Xs1VMQlhsga57AACSS8"]
[Mon Jun 15 20:19:19.810882 2026] [security2:error] [pid 51003:tid 51200] [client 57.141.14.16:65474] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyp8psKyvb75pkSvabNwAB0kc"]
[Mon Jun 15 20:19:19.919834 2026] [security2:error] [pid 51003:tid 51133] [client 139.99.122.191:56904] ModSecurity: Access denied with code 406 (phase 1). Pattern match "xmlrpc\\\\.php" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "73"] [id "392331"] [rev "3"] [msg "Atomicorp.com WAF Rules: xmlrpc DOS attack"] [severity "CRITICAL"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCyp8psKyvb75pkSvabRAAAAY8"]
[Mon Jun 15 20:19:19.923218 2026] [security2:error] [pid 53359:tid 53565] [client 139.99.122.191:56914] ModSecurity: Access denied with code 406 (phase 1). Pattern match "xmlrpc\\\\.php" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "73"] [id "392331"] [rev "3"] [msg "Atomicorp.com WAF Rules: xmlrpc DOS attack"] [severity "CRITICAL"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCyp_C2Xs1VMQlhsga6AwAAAlo"]
[Mon Jun 15 20:19:19.923311 2026] [security2:error] [pid 53359:tid 53565] [client 139.99.122.191:56914] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCyp_C2Xs1VMQlhsga6AwAAAlo"]
[Mon Jun 15 20:19:19.932568 2026] [security2:error] [pid 51003:tid 51133] [client 139.99.122.191:56904] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCyp8psKyvb75pkSvabRAAAAY8"]
[Mon Jun 15 20:19:19.944524 2026] [security2:error] [pid 51003:tid 51252] [client 139.99.122.191:56906] ModSecurity: Access denied with code 406 (phase 1). Pattern match "xmlrpc\\\\.php" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "73"] [id "392331"] [rev "3"] [msg "Atomicorp.com WAF Rules: xmlrpc DOS attack"] [severity "CRITICAL"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCyp8psKyvb75pkSvabRgAAAgY"]
[Mon Jun 15 20:19:19.981509 2026] [security2:error] [pid 51003:tid 51252] [client 139.99.122.191:56906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCyp8psKyvb75pkSvabRgAAAgY"]
[Mon Jun 15 20:19:20.021122 2026] [security2:error] [pid 51003:tid 51217] [client 103.125.146.45:61093] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/chaqsd.php"] [unique_id "ajCyqMpsKyvb75pkSvabSAAAAeM"]
[Mon Jun 15 20:19:20.350311 2026] [security2:error] [pid 53359:tid 53586] [client 142.248.80.104:40776] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcontacts.convertease.us"] [uri "/___proxy_subdomain_cpcontacts/.env.production~"] [unique_id "ajCyqPC2Xs1VMQlhsga6DQAAAm8"]
[Mon Jun 15 20:19:20.350314 2026] [security2:error] [pid 53359:tid 53508] [client 142.248.80.104:40718] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcontacts.convertease.us"] [uri "/___proxy_subdomain_cpcontacts/.env.local.orig"] [unique_id "ajCyqPC2Xs1VMQlhsga6EAAAAiE"]
[Mon Jun 15 20:19:20.350315 2026] [security2:error] [pid 51003:tid 51254] [client 142.248.80.104:40806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcontacts.convertease.us"] [uri "/___proxy_subdomain_cpcontacts/.env.production.orig"] [unique_id "ajCyqMpsKyvb75pkSvabTwAAAgg"]
[Mon Jun 15 20:19:20.350317 2026] [security2:error] [pid 53359:tid 53537] [client 142.248.80.104:40706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcontacts.convertease.us"] [uri "/___proxy_subdomain_cpcontacts/.env.local.swp"] [unique_id "ajCyqPC2Xs1VMQlhsga6DwAAAj4"]
[Mon Jun 15 20:19:20.350378 2026] [security2:error] [pid 53359:tid 53512] [client 142.248.80.104:40790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcontacts.convertease.us"] [uri "/___proxy_subdomain_cpcontacts/.env.production.swp"] [unique_id "ajCyqPC2Xs1VMQlhsga6DgAAAiU"]
[Mon Jun 15 20:19:20.350757 2026] [proxy:error] [pid 51003:tid 51179] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:20.350809 2026] [proxy:error] [pid 53359:tid 53554] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:20.350833 2026] [proxy_http:error] [pid 51003:tid 51179] [client 142.248.80.104:40764] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:20.350861 2026] [proxy_http:error] [pid 53359:tid 53554] [client 142.248.80.104:40632] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:20.350948 2026] [proxy:error] [pid 53359:tid 53581] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:20.350969 2026] [security2:error] [pid 53359:tid 53608] [client 142.248.80.104:40744] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcontacts.convertease.us"] [uri "/___proxy_subdomain_cpcontacts/.env.production.bak"] [unique_id "ajCyqPC2Xs1VMQlhsga6EQAAAoU"]
[Mon Jun 15 20:19:20.350999 2026] [proxy_http:error] [pid 53359:tid 53581] [client 142.248.80.104:40642] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:20.351042 2026] [security2:error] [pid 51003:tid 51225] [client 142.248.80.104:40584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpcontacts.convertease.us"] [uri "/___proxy_subdomain_cpcontacts/.env.production.copy"] [unique_id "ajCyqMpsKyvb75pkSvabUAAAAes"]
[Mon Jun 15 20:19:20.351503 2026] [proxy:error] [pid 53359:tid 53554] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:20.351517 2026] [proxy:error] [pid 51003:tid 51179] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:20.351533 2026] [proxy_http:error] [pid 53359:tid 53554] [client 142.248.80.104:40632] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:20.351553 2026] [proxy_http:error] [pid 51003:tid 51179] [client 142.248.80.104:40764] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:20.351644 2026] [proxy:error] [pid 53359:tid 53581] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:20.351679 2026] [proxy_http:error] [pid 53359:tid 53581] [client 142.248.80.104:40642] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:20.351819 2026] [security2:error] [pid 53359:tid 53517] [client 142.248.80.104:40660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcontacts.convertease.us"] [uri "/___proxy_subdomain_cpcontacts/.env.orig"] [unique_id "ajCyqPC2Xs1VMQlhsga6FQAAAio"]
[Mon Jun 15 20:19:20.351888 2026] [security2:error] [pid 53359:tid 53530] [client 142.248.80.104:40732] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpcontacts.convertease.us"] [uri "/___proxy_subdomain_cpcontacts/.env.local.copy"] [unique_id "ajCyqPC2Xs1VMQlhsga6FAAAAjc"]
[Mon Jun 15 20:19:20.352019 2026] [proxy:error] [pid 53359:tid 53594] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:20.352056 2026] [proxy_http:error] [pid 53359:tid 53594] [client 142.248.80.104:40694] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:20.352355 2026] [security2:error] [pid 53359:tid 53553] [client 142.248.80.104:40648] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcontacts.convertease.us"] [uri "/___proxy_subdomain_cpcontacts/.env.swp"] [unique_id "ajCyqPC2Xs1VMQlhsga6FwAAAk4"]
[Mon Jun 15 20:19:20.352462 2026] [security2:error] [pid 51003:tid 51169] [client 142.248.80.104:40688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcontacts.convertease.us"] [uri "/___proxy_subdomain_cpcontacts/.env.local.old"] [unique_id "ajCyqMpsKyvb75pkSvabUQAAAbM"]
[Mon Jun 15 20:19:20.352558 2026] [security2:error] [pid 53359:tid 53505] [client 142.248.80.104:40750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcontacts.convertease.us"] [uri "/___proxy_subdomain_cpcontacts/.env.production.old"] [unique_id "ajCyqPC2Xs1VMQlhsga6GQAAAh4"]
[Mon Jun 15 20:19:20.352652 2026] [security2:error] [pid 53359:tid 53514] [client 142.248.80.104:40690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcontacts.convertease.us"] [uri "/___proxy_subdomain_cpcontacts/.env.local.backup"] [unique_id "ajCyqPC2Xs1VMQlhsga6GAAAAic"]
[Mon Jun 15 20:19:20.352763 2026] [proxy:error] [pid 53359:tid 53594] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:20.352798 2026] [proxy_http:error] [pid 53359:tid 53594] [client 142.248.80.104:40694] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:20.352843 2026] [security2:error] [pid 53359:tid 53598] [client 142.248.80.104:40758] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcontacts.convertease.us"] [uri "/___proxy_subdomain_cpcontacts/.env.production.backup"] [unique_id "ajCyqPC2Xs1VMQlhsga6GwAAAns"]
[Mon Jun 15 20:19:20.352889 2026] [proxy:error] [pid 53359:tid 53555] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:20.352929 2026] [proxy_http:error] [pid 53359:tid 53555] [client 142.248.80.104:40606] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:20.353184 2026] [security2:error] [pid 53359:tid 53619] [client 142.248.80.104:40700] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcontacts.convertease.us"] [uri "/___proxy_subdomain_cpcontacts/.env.local~"] [unique_id "ajCyqPC2Xs1VMQlhsga6HAAAApA"]
[Mon Jun 15 20:19:20.353220 2026] [security2:error] [pid 53359:tid 53614] [client 142.248.80.104:40682] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcontacts.convertease.us"] [uri "/___proxy_subdomain_cpcontacts/.env.local.bak"] [unique_id "ajCyqPC2Xs1VMQlhsga6HQAAAos"]
[Mon Jun 15 20:19:20.353554 2026] [proxy:error] [pid 53359:tid 53555] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:20.353581 2026] [proxy_http:error] [pid 53359:tid 53555] [client 142.248.80.104:40606] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:20.353609 2026] [security2:error] [pid 53359:tid 53587] [client 142.248.80.104:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpcontacts.convertease.us"] [uri "/___proxy_subdomain_cpcontacts/.env.copy"] [unique_id "ajCyqPC2Xs1VMQlhsga6HgAAAnA"]
[Mon Jun 15 20:19:20.353734 2026] [proxy:error] [pid 53359:tid 53602] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:20.353783 2026] [proxy_http:error] [pid 53359:tid 53602] [client 142.248.80.104:40598] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:20.354168 2026] [security2:error] [pid 51003:tid 51255] [client 142.248.80.104:40646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcontacts.convertease.us"] [uri "/___proxy_subdomain_cpcontacts/.env~"] [unique_id "ajCyqMpsKyvb75pkSvabUgAAAgk"]
[Mon Jun 15 20:19:20.354221 2026] [proxy:error] [pid 53359:tid 53602] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:20.354248 2026] [proxy_http:error] [pid 53359:tid 53602] [client 142.248.80.104:40598] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:20.354537 2026] [proxy:error] [pid 53359:tid 53561] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:20.354587 2026] [proxy_http:error] [pid 53359:tid 53561] [client 142.248.80.104:40612] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:20.355236 2026] [proxy:error] [pid 53359:tid 53561] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:20.355277 2026] [proxy_http:error] [pid 53359:tid 53561] [client 142.248.80.104:40612] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:20.386926 2026] [security2:error] [pid 51003:tid 51138] [client 109.70.100.1:57694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.100.70.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arasansoap.com"] [uri "/xmlrpc.php"] [unique_id "ajCyqMpsKyvb75pkSvabVAAAAZQ"], referer: https://arasansoap.com/
[Mon Jun 15 20:19:20.387045 2026] [security2:error] [pid 51003:tid 51138] [client 109.70.100.1:57694] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arasansoap.com"] [uri "/xmlrpc.php"] [unique_id "ajCyqMpsKyvb75pkSvabVAAAAZQ"], referer: https://arasansoap.com/
[Mon Jun 15 20:19:20.397714 2026] [security2:error] [pid 51003:tid 51249] [client 103.125.146.52:54451] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/interactivity-api/interactivity-api-core.php"] [unique_id "ajCyqMpsKyvb75pkSvabVgAAAgM"]
[Mon Jun 15 20:19:20.447334 2026] [security2:error] [pid 53359:tid 53446] [remote 43.172.197.62:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.197.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mywordsnthoughts.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ajCyqPC2Xs1VMQlhsga6IQACZlA"], referer: https://mywordsnthoughts.com/stuffed-pomfret-stuffed-avoli/
[Mon Jun 15 20:19:20.452529 2026] [proxy:error] [pid 53359:tid 53575] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:20.452599 2026] [proxy_http:error] [pid 53359:tid 53575] [client 142.248.80.104:40622] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:20.453691 2026] [proxy:error] [pid 53359:tid 53575] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:20.453725 2026] [proxy_http:error] [pid 53359:tid 53575] [client 142.248.80.104:40622] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:20.559349 2026] [core:error] [pid 53359:tid 53603] [client 9.169.124.50:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jun 15 20:19:20.559380 2026] [core:error] [pid 53359:tid 53603] [client 9.169.124.50:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jun 15 20:19:20.814766 2026] [security2:error] [pid 53359:tid 53533] [client 103.125.146.78:26783] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-admin/setup-config-framework.php"] [unique_id "ajCyqPC2Xs1VMQlhsga6NAAAAjo"]
[Mon Jun 15 20:19:20.841760 2026] [security2:error] [pid 53359:tid 53618] [client 38.159.57.105:56594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "wantpg.com"] [uri "/public/index.php/pg-in-ilchultong-1337049"] [unique_id "ajCyqPC2Xs1VMQlhsga6NQAAAo8"]
[Mon Jun 15 20:19:20.905762 2026] [security2:error] [pid 53359:tid 53519] [client 43.172.196.162:33948] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "itdeed.com"] [uri "/demomahayogini/wp-content/plugins/woocommerce-product-addon/backend/assets/tooltip/tooltip.css"] [unique_id "ajCyqPC2Xs1VMQlhsga6OQAAAiw"], referer: https://itdeed.com/demomahayogini/product/%F0%9F%95%89%EF%B8%8F-arisht-gun-dosh-nivaran-puja-and-homam/
[Mon Jun 15 20:19:21.051631 2026] [security2:error] [pid 53359:tid 53566] [client 43.173.174.74:51968] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "itdeed.com"] [uri "/demomahayogini/wp-content/plugins/woocommerce-product-addon/css/bootstrap/bootstrap.css"] [unique_id "ajCyqfC2Xs1VMQlhsga6PgAAAls"], referer: https://itdeed.com/demomahayogini/product/%F0%9F%95%89%EF%B8%8F-arisht-gun-dosh-nivaran-puja-and-homam/
[Mon Jun 15 20:19:21.057490 2026] [security2:error] [pid 53359:tid 53548] [client 43.173.179.9:41182] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "itdeed.com"] [uri "/demomahayogini/wp-content/plugins/woocommerce-product-addon/css/ppom-simple-popup.css"] [unique_id "ajCyqfC2Xs1VMQlhsga6PwAAAkk"], referer: https://itdeed.com/demomahayogini/product/%F0%9F%95%89%EF%B8%8F-arisht-gun-dosh-nivaran-puja-and-homam/
[Mon Jun 15 20:19:21.205138 2026] [security2:error] [pid 53359:tid 53584] [client 103.125.146.73:65077] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/canonical-loop.php"] [unique_id "ajCyqfC2Xs1VMQlhsga6QwAAAm0"]
[Mon Jun 15 20:19:21.319155 2026] [security2:error] [pid 53359:tid 53497] [client 43.172.194.62:55322] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "itdeed.com"] [uri "/demomahayogini/wp-content/plugins/woocommerce-product-addon/css/bootstrap/bootstrap.modal.css"] [unique_id "ajCyqfC2Xs1VMQlhsga6RgAAAhY"], referer: https://itdeed.com/demomahayogini/product/%F0%9F%95%89%EF%B8%8F-arisht-gun-dosh-nivaran-puja-and-homam/
[Mon Jun 15 20:19:21.405520 2026] [security2:error] [pid 51003:tid 51127] [remote 57.141.14.28:57712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.14.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wilsonoverseas.com"] [uri "/items/K414993537"] [unique_id "ajCyqcpsKyvb75pkSvabZwABtXs"]
[Mon Jun 15 20:19:21.545769 2026] [security2:error] [pid 51003:tid 51154] [client 47.79.206.110:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "societytodaynews.com"] [uri "/index.php"] [unique_id "ajCyqcpsKyvb75pkSvabZQAAAaQ"], referer: https://www.google.com/
[Mon Jun 15 20:19:21.592423 2026] [security2:error] [pid 51003:tid 51139] [client 103.125.146.76:48105] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/block-supports/align-query.php"] [unique_id "ajCyqcpsKyvb75pkSvabaAAAAZU"]
[Mon Jun 15 20:19:21.657506 2026] [security2:error] [pid 53359:tid 53522] [client 126.209.47.75:60690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.47.209.126.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nxtal.com"] [uri "/xmlrpc.php"] [unique_id "ajCyqfC2Xs1VMQlhsga6UAAAAi8"]
[Mon Jun 15 20:19:21.657819 2026] [security2:error] [pid 53359:tid 53522] [client 126.209.47.75:60690] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nxtal.com"] [uri "/xmlrpc.php"] [unique_id "ajCyqfC2Xs1VMQlhsga6UAAAAi8"]
[Mon Jun 15 20:19:21.666758 2026] [security2:error] [pid 53359:tid 53598] [client 57.141.14.48:60487] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyqfC2Xs1VMQlhsga6SgACe3U"]
[Mon Jun 15 20:19:21.719131 2026] [security2:error] [pid 51003:tid 51181] [client 57.141.14.24:63442] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "wantpg.com"] [uri "/public/index.php/in/ban-bing-sisaket-thailand-2354585.html"] [unique_id "ajCyqcpsKyvb75pkSvabawABv0Y"]
[Mon Jun 15 20:19:21.734091 2026] [security2:error] [pid 53359:tid 53586] [client 192.140.64.94:29845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.64.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCyqfC2Xs1VMQlhsga6VAAAAm8"]
[Mon Jun 15 20:19:21.736858 2026] [security2:error] [pid 53359:tid 53586] [client 192.140.64.94:29845] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCyqfC2Xs1VMQlhsga6VAAAAm8"]
[Mon Jun 15 20:19:21.738567 2026] [security2:error] [pid 53359:tid 53441] [remote 152.53.111.131:48034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.111.53.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "makhanamantra.com"] [uri "/wp-login.php"] [unique_id "ajCyqfC2Xs1VMQlhsga6UwACJ0s"]
[Mon Jun 15 20:19:21.998917 2026] [security2:error] [pid 53359:tid 53379] [remote 152.53.111.131:48034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.111.53.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "makhanamantra.com"] [uri "/wp-login.php"] [unique_id "ajCyqfC2Xs1VMQlhsga6WAACaA0"], referer: https://makhanamantra.com/wp-login.php
[Mon Jun 15 20:19:22.019897 2026] [security2:error] [pid 53359:tid 53536] [client 103.125.146.55:48401] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/blocks/button-core.php"] [unique_id "ajCyqvC2Xs1VMQlhsga6WQAAAj0"]
[Mon Jun 15 20:19:22.158986 2026] [security2:error] [pid 53359:tid 53534] [client 213.230.76.221:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kthemani.com"] [uri "/index.php"] [unique_id "ajCyqPC2Xs1VMQlhsga6CwAAAjs"]
[Mon Jun 15 20:19:22.210014 2026] [security2:error] [pid 51003:tid 51022] [remote 110.249.201.146:49328] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.steelsalesco.com"] [uri "/super-duplex-steel-s32750-pipe-fittings-supplier-manufacturer/"] [unique_id "ajCyqspsKyvb75pkSvabdgAB1RI"]
[Mon Jun 15 20:19:22.211312 2026] [security2:error] [pid 53359:tid 53454] [remote 43.173.182.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.182.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mywordsnthoughts.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ajCyqvC2Xs1VMQlhsga6YQACFFg"], referer: https://mywordsnthoughts.com/bread-rolls-fried/
[Mon Jun 15 20:19:22.361282 2026] [security2:error] [pid 51003:tid 51252] [client 57.141.14.80:27729] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyqspsKyvb75pkSvabeAACBgQ"]
[Mon Jun 15 20:19:22.361415 2026] [security2:error] [pid 53359:tid 53529] [client 103.65.237.194:51869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.237.65.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tretaillabs.com"] [uri "/wp-login.php"] [unique_id "ajCyqvC2Xs1VMQlhsga6YwAAAjY"]
[Mon Jun 15 20:19:22.408608 2026] [security2:error] [pid 51003:tid 51188] [client 103.125.146.70:63091] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-admin/includes/translation-install-stat.php"] [unique_id "ajCyqspsKyvb75pkSvabfAAAAcY"]
[Mon Jun 15 20:19:22.718685 2026] [security2:error] [pid 51003:tid 51072] [remote 64.131.86.2:38096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.86.131.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.d-lloydmembershipcost.co.uk"] [uri "/wp-login.php"] [unique_id "ajCyqspsKyvb75pkSvabgAAB8UQ"]
[Mon Jun 15 20:19:22.822331 2026] [security2:error] [pid 53359:tid 53587] [client 103.125.146.50:52765] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-admin/network/users-wp-info.php"] [unique_id "ajCyqvC2Xs1VMQlhsga6cwAAAnA"]
[Mon Jun 15 20:19:22.907062 2026] [security2:error] [pid 51003:tid 51009] [remote 64.131.86.2:38096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.86.131.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.d-lloydmembershipcost.co.uk"] [uri "/wp-login.php"] [unique_id "ajCyqspsKyvb75pkSvabggABqgU"], referer: https://mail.d-lloydmembershipcost.co.uk/wp-login.php
[Mon Jun 15 20:19:22.940031 2026] [security2:error] [pid 53359:tid 53463] [remote 148.66.130.53:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.130.66.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "coachsrikanth.com"] [uri "/wp-login.php"] [unique_id "ajCyqvC2Xs1VMQlhsga6dgACYWE"]
[Mon Jun 15 20:19:23.115555 2026] [security2:error] [pid 53359:tid 53512] [client 49.37.157.202:59990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "desidelightmp.com"] [uri "/xmlrpc.php"] [unique_id "ajCyq_C2Xs1VMQlhsga6fAAAAiU"]
[Mon Jun 15 20:19:23.115663 2026] [security2:error] [pid 53359:tid 53512] [client 49.37.157.202:59990] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "desidelightmp.com"] [uri "/xmlrpc.php"] [unique_id "ajCyq_C2Xs1VMQlhsga6fAAAAiU"]
[Mon Jun 15 20:19:23.234515 2026] [security2:error] [pid 51003:tid 51204] [client 103.125.146.70:26127] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/class.wp-styles-branch.php"] [unique_id "ajCyq8psKyvb75pkSvabiwAAAdY"]
[Mon Jun 15 20:19:23.348350 2026] [security2:error] [pid 53359:tid 53400] [remote 148.66.130.53:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.130.66.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "coachsrikanth.com"] [uri "/wp-login.php"] [unique_id "ajCyq_C2Xs1VMQlhsga6ggACkiI"], referer: https://coachsrikanth.com/wp-login.php
[Mon Jun 15 20:19:23.622993 2026] [security2:error] [pid 51003:tid 51211] [client 103.125.146.38:20947] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-admin/contribute-cookie.php"] [unique_id "ajCyq8psKyvb75pkSvabkgAAAd0"]
[Mon Jun 15 20:19:24.011817 2026] [security2:error] [pid 53359:tid 53610] [client 103.125.146.50:48449] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/blocks/site-title-reference.php"] [unique_id "ajCyrPC2Xs1VMQlhsga6lQAAAoc"]
[Mon Jun 15 20:19:24.390654 2026] [security2:error] [pid 51003:tid 51179] [client 139.99.122.191:57224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.122.99.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srinivasgorthyandco.com"] [uri "/wp-login.php"] [unique_id "ajCyrMpsKyvb75pkSvaboAAAAb0"]
[Mon Jun 15 20:19:24.391582 2026] [security2:error] [pid 53359:tid 53559] [client 139.99.122.191:57212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.122.99.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srinivasgorthyandco.com"] [uri "/wp-login.php"] [unique_id "ajCyrPC2Xs1VMQlhsga6pwAAAlQ"]
[Mon Jun 15 20:19:24.397187 2026] [security2:error] [pid 51003:tid 51225] [client 139.99.122.191:57202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.122.99.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srinivasgorthyandco.com"] [uri "/wp-login.php"] [unique_id "ajCyrMpsKyvb75pkSvaboQAAAes"]
[Mon Jun 15 20:19:24.420609 2026] [security2:error] [pid 51003:tid 51216] [client 103.125.146.75:30741] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/uploads/profile.php"] [unique_id "ajCyrMpsKyvb75pkSvabowAAAeI"]
[Mon Jun 15 20:19:24.446899 2026] [proxy:error] [pid 53359:tid 53564] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:24.446986 2026] [proxy_http:error] [pid 53359:tid 53564] [client 142.248.80.104:40682] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:24.448685 2026] [proxy:error] [pid 53359:tid 53564] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:24.448743 2026] [proxy_http:error] [pid 53359:tid 53564] [client 142.248.80.104:40682] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:24.457901 2026] [security2:error] [pid 53359:tid 53498] [client 57.141.14.112:23484] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyrPC2Xs1VMQlhsga6owACF0E"]
[Mon Jun 15 20:19:24.723764 2026] [security2:error] [pid 51003:tid 51147] [client 47.79.201.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thetravellingpages.com"] [uri "/index.php"] [unique_id "ajCyqspsKyvb75pkSvabdQABnWs"], referer: https://www.google.com/
[Mon Jun 15 20:19:24.828907 2026] [security2:error] [pid 53359:tid 53596] [client 103.125.146.58:49713] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/images/media/min.php"] [unique_id "ajCyrPC2Xs1VMQlhsga6vwAAAnk"]
[Mon Jun 15 20:19:25.035594 2026] [security2:error] [pid 53359:tid 53528] [client 172.59.113.191:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kthemani.com"] [uri "/index.php"] [unique_id "ajCyq_C2Xs1VMQlhsga6egACNQg"]
[Mon Jun 15 20:19:25.215891 2026] [security2:error] [pid 53359:tid 53534] [client 103.125.146.42:44167] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/xroot.php"] [unique_id "ajCyrfC2Xs1VMQlhsga6xQAAAjs"]
[Mon Jun 15 20:19:25.438496 2026] [security2:error] [pid 53359:tid 53399] [remote 184.107.244.93:39678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.244.107.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dountsmenu.onl"] [uri "/wp-login.php"] [unique_id "ajCyrfC2Xs1VMQlhsga6yAACLCE"]
[Mon Jun 15 20:19:25.585887 2026] [security2:error] [pid 53359:tid 53598] [client 103.125.146.61:50951] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/asy.php"] [unique_id "ajCyrfC2Xs1VMQlhsga6ygAAAns"]
[Mon Jun 15 20:19:25.648954 2026] [security2:error] [pid 53359:tid 53448] [remote 184.107.244.93:39678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.244.107.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dountsmenu.onl"] [uri "/wp-login.php"] [unique_id "ajCyrfC2Xs1VMQlhsga6zwACGFI"], referer: https://dountsmenu.onl/wp-login.php
[Mon Jun 15 20:19:25.741028 2026] [security2:error] [pid 53359:tid 53594] [client 139.99.122.191:57274] ModSecurity: Access denied with code 406 (phase 1). Pattern match "xmlrpc\\\\.php" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "73"] [id "392331"] [rev "3"] [msg "Atomicorp.com WAF Rules: xmlrpc DOS attack"] [severity "CRITICAL"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCyrfC2Xs1VMQlhsga60AAAAnc"]
[Mon Jun 15 20:19:25.749649 2026] [security2:error] [pid 51003:tid 51160] [client 65.111.30.222:13953] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.procrastinatingworker.imcorp.in"] [uri "/index.php"] [unique_id "ajCyrcpsKyvb75pkSvabwwAAAao"]
[Mon Jun 15 20:19:25.763330 2026] [security2:error] [pid 53359:tid 53594] [client 139.99.122.191:57274] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCyrfC2Xs1VMQlhsga60AAAAnc"]
[Mon Jun 15 20:19:25.931179 2026] [security2:error] [pid 51003:tid 51083] [remote 57.141.14.24:63448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyrcpsKyvb75pkSvabxQABtk8"]
[Mon Jun 15 20:19:26.018285 2026] [security2:error] [pid 53359:tid 53505] [client 103.125.146.74:46807] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-admin/css/colors/ocean/cong.php"] [unique_id "ajCyrvC2Xs1VMQlhsga62AAAAh4"]
[Mon Jun 15 20:19:26.277604 2026] [security2:error] [pid 53359:tid 53482] [remote 68.178.160.25:45484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myexcelguide.com"] [uri "/wp-login.php"] [unique_id "ajCyrvC2Xs1VMQlhsga64QACi3Q"]
[Mon Jun 15 20:19:26.368313 2026] [security2:error] [pid 51003:tid 51201] [client 47.79.206.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "societytodaynews.com"] [uri "/index.php"] [unique_id "ajCyrspsKyvb75pkSvabzQAAAdM"], referer: https://www.google.com/
[Mon Jun 15 20:19:26.397402 2026] [security2:error] [pid 51003:tid 51205] [client 139.99.122.191:57480] ModSecurity: Access denied with code 406 (phase 1). Pattern match "xmlrpc\\\\.php" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "73"] [id "392331"] [rev "3"] [msg "Atomicorp.com WAF Rules: xmlrpc DOS attack"] [severity "CRITICAL"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCyrspsKyvb75pkSvab0gAAAdc"]
[Mon Jun 15 20:19:26.397495 2026] [security2:error] [pid 51003:tid 51205] [client 139.99.122.191:57480] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCyrspsKyvb75pkSvab0gAAAdc"]
[Mon Jun 15 20:19:26.429834 2026] [security2:error] [pid 53359:tid 53611] [client 103.125.146.76:45777] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/blocks/pullquote/aj.php"] [unique_id "ajCyrvC2Xs1VMQlhsga67AAAAog"]
[Mon Jun 15 20:19:26.642259 2026] [security2:error] [pid 51003:tid 51175] [client 139.99.122.191:57534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.122.99.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srinivasgorthyandco.com"] [uri "/wp-login.php"] [unique_id "ajCyrspsKyvb75pkSvab3AAAAbk"]
[Mon Jun 15 20:19:26.912897 2026] [security2:error] [pid 51003:tid 51203] [client 103.125.146.38:25775] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/sitemaps/providers/wp-login.php"] [unique_id "ajCyrspsKyvb75pkSvab3QAAAdU"]
[Mon Jun 15 20:19:27.040419 2026] [proxy:error] [pid 51003:tid 51233] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:27.040482 2026] [proxy_http:error] [pid 51003:tid 51233] [client 87.236.176.51:36035] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:27.040973 2026] [proxy:error] [pid 51003:tid 51233] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jun 15 20:19:27.040997 2026] [proxy_http:error] [pid 51003:tid 51233] [client 87.236.176.51:36035] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jun 15 20:19:27.078705 2026] [security2:error] [pid 53359:tid 53367] [remote 43.173.178.91:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.178.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mywordsnthoughts.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ajCyr_C2Xs1VMQlhsga7BgACZQE"], referer: https://mywordsnthoughts.com/observe-these-phases-as-your-infant-grows/
[Mon Jun 15 20:19:27.244372 2026] [security2:error] [pid 53359:tid 53606] [client 57.141.14.72:30607] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyr_C2Xs1VMQlhsga7DgACgw8"]
[Mon Jun 15 20:19:27.252045 2026] [security2:error] [pid 53359:tid 53504] [client 139.99.122.191:57652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.122.99.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srinivasgorthyandco.com"] [uri "/wp-login.php"] [unique_id "ajCyr_C2Xs1VMQlhsga7DwAAAh0"]
[Mon Jun 15 20:19:27.285289 2026] [security2:error] [pid 53359:tid 53562] [client 103.125.146.66:35433] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-admin/user/cjfuns.php"] [unique_id "ajCyr_C2Xs1VMQlhsga7EgAAAlc"]
[Mon Jun 15 20:19:27.721943 2026] [security2:error] [pid 53359:tid 53567] [client 103.125.146.66:39777] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-cron-element.php"] [unique_id "ajCyr_C2Xs1VMQlhsga7NQAAAlw"]
[Mon Jun 15 20:19:27.884762 2026] [security2:error] [pid 51003:tid 51085] [remote 74.208.38.160:39978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.38.208.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myexcelguide.com"] [uri "/wp-login.php"] [unique_id "ajCyr8psKyvb75pkSvab_QAB6lE"]
[Mon Jun 15 20:19:28.046537 2026] [security2:error] [pid 53359:tid 53612] [client 43.173.173.77:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCyr_C2Xs1VMQlhsga7NAACiRs"]
[Mon Jun 15 20:19:28.105288 2026] [security2:error] [pid 53359:tid 53505] [client 103.125.146.30:53071] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/fonts/zoom.php"] [unique_id "ajCysPC2Xs1VMQlhsga7QgAAAh4"]
[Mon Jun 15 20:19:28.139198 2026] [security2:error] [pid 51003:tid 51243] [client 31.219.209.201:55469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.209.219.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCysMpsKyvb75pkSvacDAAAAf0"]
[Mon Jun 15 20:19:28.139319 2026] [security2:error] [pid 51003:tid 51243] [client 31.219.209.201:55469] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCysMpsKyvb75pkSvacDAAAAf0"]
[Mon Jun 15 20:19:28.140139 2026] [security2:error] [pid 53359:tid 53395] [remote 2a03:2880:f806:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ruchini.hemani.finance"] [uri "/index.php"] [unique_id "ajCyr_C2Xs1VMQlhsga7PQACbR0"]
[Mon Jun 15 20:19:28.486663 2026] [security2:error] [pid 53359:tid 53572] [client 103.125.146.52:58541] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/backup-migration/admin.php"] [unique_id "ajCysPC2Xs1VMQlhsga7SAAAAmE"]
[Mon Jun 15 20:19:28.652377 2026] [security2:error] [pid 51003:tid 51250] [client 20.229.212.220:50575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.212.229.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "archresource.co"] [uri "/100.php"] [unique_id "ajCysMpsKyvb75pkSvacFQAAAgQ"]
[Mon Jun 15 20:19:28.757602 2026] [security2:error] [pid 53359:tid 53522] [client 57.141.14.97:55840] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCysPC2Xs1VMQlhsga7VAACLyU"]
[Mon Jun 15 20:19:28.890089 2026] [security2:error] [pid 53359:tid 53531] [client 103.125.146.58:22739] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/js/jcrop/config.php"] [unique_id "ajCysPC2Xs1VMQlhsga7WwAAAjg"]
[Mon Jun 15 20:19:29.070482 2026] [security2:error] [pid 51003:tid 51188] [client 172.59.12.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kthemani.com"] [uri "/index.php"] [unique_id "ajCyr8psKyvb75pkSvab5gAAAcY"]
[Mon Jun 15 20:19:29.151312 2026] [autoindex:error] [pid 53359:tid 53423] [remote 40.77.167.12:0] AH01276: Cannot serve directory /home1/erjavlmy/public_html/us-fayajewels/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jun 15 20:19:29.292898 2026] [security2:error] [pid 53359:tid 53594] [client 103.125.146.62:49067] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/widgets/login.php"] [unique_id "ajCysfC2Xs1VMQlhsga7awAAAnc"]
[Mon Jun 15 20:19:29.513486 2026] [security2:error] [pid 53359:tid 53577] [client 172.225.201.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "enterkit.in"] [uri "/index.php"] [unique_id "ajCysPC2Xs1VMQlhsga7VwACZlY"]
[Mon Jun 15 20:19:29.592043 2026] [security2:error] [pid 53359:tid 53617] [client 139.99.122.191:57898] ModSecurity: Access denied with code 406 (phase 1). Pattern match "xmlrpc\\\\.php" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "73"] [id "392331"] [rev "3"] [msg "Atomicorp.com WAF Rules: xmlrpc DOS attack"] [severity "CRITICAL"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCysfC2Xs1VMQlhsga7ewAAAo4"]
[Mon Jun 15 20:19:29.598880 2026] [security2:error] [pid 53359:tid 53499] [client 20.229.212.220:51201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.212.229.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "archresource.co"] [uri "/elp.php"] [unique_id "ajCysfC2Xs1VMQlhsga7gAAAAhg"]
[Mon Jun 15 20:19:29.611127 2026] [security2:error] [pid 53359:tid 53617] [client 139.99.122.191:57898] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCysfC2Xs1VMQlhsga7ewAAAo4"]
[Mon Jun 15 20:19:29.624200 2026] [security2:error] [pid 51003:tid 51169] [client 43.172.196.140:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "itdeed.com"] [uri "/demomahayogini/product-tag/vishnu-sahasranama-chanting"] [unique_id "ajCyscpsKyvb75pkSvacJQAAAbM"]
[Mon Jun 15 20:19:29.709110 2026] [security2:error] [pid 53359:tid 53576] [client 57.141.14.62:39108] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rohandasgupta.com"] [uri "/index.php"] [unique_id "ajCysfC2Xs1VMQlhsga7dAACZX8"]
[Mon Jun 15 20:19:29.712058 2026] [security2:error] [pid 51003:tid 51213] [client 103.125.146.74:53457] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/rest-api/config.php"] [unique_id "ajCyscpsKyvb75pkSvacKQAAAd8"]
[Mon Jun 15 20:19:29.834328 2026] [security2:error] [pid 51003:tid 51017] [remote 192.169.174.130:16008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.174.169.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hydlab.in"] [uri "/wp-login.php"] [unique_id "ajCyscpsKyvb75pkSvacLAABsA0"]
[Mon Jun 15 20:19:29.999437 2026] [security2:error] [pid 53359:tid 53508] [client 57.141.14.79:36914] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCysfC2Xs1VMQlhsga7kAACIU8"]
[Mon Jun 15 20:19:30.083885 2026] [security2:error] [pid 53359:tid 53464] [remote 66.249.70.160:0] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.smgl.org"] [uri "/robots.txt"] [unique_id "ajCysvC2Xs1VMQlhsga7kgACH2I"]
[Mon Jun 15 20:19:30.125416 2026] [security2:error] [pid 53359:tid 53619] [client 103.125.146.78:62293] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-admin/css/config.php"] [unique_id "ajCysvC2Xs1VMQlhsga7lQAAApA"]
[Mon Jun 15 20:19:30.206382 2026] [security2:error] [pid 51003:tid 51215] [client 77.68.87.67:63152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.87.68.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celticwavessc.ie"] [uri "/images/images/cache.php"] [unique_id "ajCysspsKyvb75pkSvacOAAAAeE"], referer: www.google.com
[Mon Jun 15 20:19:30.395142 2026] [security2:error] [pid 51003:tid 51204] [client 109.104.133.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCyscpsKyvb75pkSvacLQAB1hQ"], referer: https://mywordsnthoughts.com/green-mango-chutney/
[Mon Jun 15 20:19:30.437371 2026] [security2:error] [pid 51003:tid 51145] [client 109.104.133.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCyscpsKyvb75pkSvacMAABmwA"], referer: https://mywordsnthoughts.com/green-mango-chutney/
[Mon Jun 15 20:19:30.541532 2026] [security2:error] [pid 51003:tid 51253] [client 20.229.212.220:51897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.212.229.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "archresource.co"] [uri "/ftde.php"] [unique_id "ajCysspsKyvb75pkSvacQAAAAgc"]
[Mon Jun 15 20:19:30.549744 2026] [security2:error] [pid 53359:tid 53600] [client 103.125.146.74:38937] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-admin/network/config.php"] [unique_id "ajCysvC2Xs1VMQlhsga7nwAAAn0"]
[Mon Jun 15 20:19:30.962977 2026] [security2:error] [pid 53359:tid 53601] [client 103.125.146.59:36971] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/uploads/wc-logs/"] [unique_id "ajCysvC2Xs1VMQlhsga7rQAAAn4"]
[Mon Jun 15 20:19:31.317458 2026] [security2:error] [pid 51003:tid 51234] [client 57.141.14.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aarohiarts.org"] [uri "/index.php"] [unique_id "ajCys8psKyvb75pkSvacUgAAAfQ"]
[Mon Jun 15 20:19:31.325074 2026] [security2:error] [pid 53359:tid 53607] [client 103.125.146.38:46899] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/rest-api/admin.php"] [unique_id "ajCys_C2Xs1VMQlhsga7vQAAAoQ"]
[Mon Jun 15 20:19:31.330369 2026] [security2:error] [pid 53359:tid 53521] [client 72.136.123.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kthemani.com"] [uri "/index.php"] [unique_id "ajCysfC2Xs1VMQlhsga7bAACLhc"]
[Mon Jun 15 20:19:31.355462 2026] [security2:error] [pid 53359:tid 53522] [client 20.229.212.220:52682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.212.229.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "archresource.co"] [uri "/test1.php"] [unique_id "ajCys_C2Xs1VMQlhsga7vwAAAi8"]
[Mon Jun 15 20:19:31.489781 2026] [security2:error] [pid 51003:tid 51241] [client 57.141.14.102:46937] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCys8psKyvb75pkSvacYwAB-zM"]
[Mon Jun 15 20:19:31.500202 2026] [security2:error] [pid 53359:tid 53558] [client 139.99.122.191:58066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.122.99.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srinivasgorthyandco.com"] [uri "/wp-login.php"] [unique_id "ajCys_C2Xs1VMQlhsga7xQAAAlM"]
[Mon Jun 15 20:19:31.691739 2026] [security2:error] [pid 53359:tid 53616] [client 49.37.157.202:60433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "desidelightmp.com"] [uri "/xmlrpc.php"] [unique_id "ajCys_C2Xs1VMQlhsga70AAAAo0"]
[Mon Jun 15 20:19:31.691869 2026] [security2:error] [pid 53359:tid 53616] [client 49.37.157.202:60433] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "desidelightmp.com"] [uri "/xmlrpc.php"] [unique_id "ajCys_C2Xs1VMQlhsga70AAAAo0"]
[Mon Jun 15 20:19:31.734574 2026] [security2:error] [pid 51003:tid 51136] [client 103.125.146.39:34873] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/Requests/Utility/config.php"] [unique_id "ajCys8psKyvb75pkSvacbQAAAZI"]
[Mon Jun 15 20:19:32.100664 2026] [rewrite:error] [pid 53359:tid 53566] [client 47.79.198.146:39024] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:19:32.116715 2026] [security2:error] [pid 53359:tid 53506] [client 58.97.218.117:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "brainstrom.org"] [uri "/index.php"] [unique_id "ajCys_C2Xs1VMQlhsga7zQACHzQ"]
[Mon Jun 15 20:19:32.146405 2026] [security2:error] [pid 53359:tid 53557] [client 103.125.146.67:53267] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/Requests/config.php"] [unique_id "ajCytPC2Xs1VMQlhsga75wAAAlI"]
[Mon Jun 15 20:19:32.270110 2026] [security2:error] [pid 53359:tid 53577] [client 192.140.64.94:29649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.64.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCytPC2Xs1VMQlhsga78AAAAmY"]
[Mon Jun 15 20:19:32.276573 2026] [security2:error] [pid 53359:tid 53577] [client 192.140.64.94:29649] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCytPC2Xs1VMQlhsga78AAAAmY"]
[Mon Jun 15 20:19:32.517502 2026] [security2:error] [pid 51003:tid 51243] [client 20.229.212.220:53188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.212.229.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "archresource.co"] [uri "/wp-temp.php"] [unique_id "ajCytMpsKyvb75pkSvachAAAAf0"]
[Mon Jun 15 20:19:32.560159 2026] [security2:error] [pid 53359:tid 53518] [client 103.125.146.63:28383] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/widgets/config.php"] [unique_id "ajCytPC2Xs1VMQlhsga7-AAAAis"]
[Mon Jun 15 20:19:32.561934 2026] [rewrite:error] [pid 53359:tid 53595] [client 47.79.198.146:39024] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:19:32.726043 2026] [security2:error] [pid 51003:tid 51224] [client 139.99.122.191:58286] ModSecurity: Access denied with code 406 (phase 1). Pattern match "xmlrpc\\\\.php" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "73"] [id "392331"] [rev "3"] [msg "Atomicorp.com WAF Rules: xmlrpc DOS attack"] [severity "CRITICAL"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCytMpsKyvb75pkSvacigAAAeo"]
[Mon Jun 15 20:19:32.726199 2026] [security2:error] [pid 51003:tid 51224] [client 139.99.122.191:58286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCytMpsKyvb75pkSvacigAAAeo"]
[Mon Jun 15 20:19:32.782160 2026] [security2:error] [pid 53359:tid 53382] [remote 57.141.14.77:20417] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCytPC2Xs1VMQlhsga7-gACMhA"]
[Mon Jun 15 20:19:32.839409 2026] [security2:error] [pid 53359:tid 53513] [client 49.51.51.17:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "itdeed.com"] [uri "/demomahayogini/product-tag/vishnu-sahasranama-chanting"] [unique_id "ajCytPC2Xs1VMQlhsga7_wAAAiY"]
[Mon Jun 15 20:19:32.962068 2026] [security2:error] [pid 53359:tid 53571] [client 103.125.146.39:58643] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/uploads/wp-config.php"] [unique_id "ajCytPC2Xs1VMQlhsga8CAAAAmA"]
[Mon Jun 15 20:19:33.005054 2026] [security2:error] [pid 53359:tid 53541] [client 9.169.124.50:24896] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.naturefarmsmart.com"] [uri "/___proxy_subdomain_webmail/"] [unique_id "ajCytPC2Xs1VMQlhsga8CQAAAkI"]
[Mon Jun 15 20:19:33.089007 2026] [security2:error] [pid 53359:tid 53601] [client 65.111.30.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.procrastinatingworker.imcorp.in"] [uri "/index.php"] [unique_id "ajCytPC2Xs1VMQlhsga8CwAAAn4"]
[Mon Jun 15 20:19:33.279257 2026] [security2:error] [pid 53359:tid 53584] [client 128.140.41.193:11636] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hanumanproperties.in"] [uri "/index.php"] [unique_id "ajCytfC2Xs1VMQlhsga8EgAAAm0"], referer: https://hanumanproperties.in
[Mon Jun 15 20:19:33.366511 2026] [security2:error] [pid 53359:tid 53366] [remote 2a03:2880:f806:f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ruchini.hemani.finance"] [uri "/index.php"] [unique_id "ajCytfC2Xs1VMQlhsga8GAACFAA"]
[Mon Jun 15 20:19:33.391274 2026] [security2:error] [pid 51003:tid 51021] [remote 192.241.157.226:40996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.157.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.captmaneshchaudarey.com"] [uri "/wp-login.php"] [unique_id "ajCytcpsKyvb75pkSvacngAB7RE"]
[Mon Jun 15 20:19:33.394437 2026] [security2:error] [pid 53359:tid 53502] [client 103.125.146.45:52567] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/js/wp-config.php"] [unique_id "ajCytfC2Xs1VMQlhsga8GgAAAhs"]
[Mon Jun 15 20:19:33.426127 2026] [rewrite:error] [pid 53359:tid 53431] [remote 47.79.197.136:46972] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:19:33.426617 2026] [security2:error] [pid 53359:tid 53554] [client 20.229.212.220:53900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.212.229.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "archresource.co"] [uri "/admin/function.php"] [unique_id "ajCytfC2Xs1VMQlhsga8HQAAAk8"]
[Mon Jun 15 20:19:33.587709 2026] [security2:error] [pid 51003:tid 51258] [client 66.249.79.167:59173] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anatma.org"] [uri "/index.php"] [unique_id "ajCytcpsKyvb75pkSvacnQAAAgw"]
[Mon Jun 15 20:19:33.600012 2026] [security2:error] [pid 51003:tid 51122] [remote 192.241.157.226:40996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.157.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.captmaneshchaudarey.com"] [uri "/wp-login.php"] [unique_id "ajCytcpsKyvb75pkSvacogAB2XY"], referer: https://mail.captmaneshchaudarey.com/wp-login.php
[Mon Jun 15 20:19:33.698665 2026] [rewrite:error] [pid 53359:tid 53373] [remote 47.79.197.136:46972] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:19:33.793368 2026] [security2:error] [pid 53359:tid 53595] [client 103.125.146.40:42679] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/js/jcrop/admin.php"] [unique_id "ajCytfC2Xs1VMQlhsga8JgAAAng"]
[Mon Jun 15 20:19:33.988002 2026] [security2:error] [pid 53359:tid 53388] [remote 74.7.242.56:53216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.242.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.softhubtechno.ehx.czu.mybluehostin.me"] [uri "/images/img/Admin/logo/images/Admin/logo/js/Admin/logo/images/clients/pms.php"] [unique_id "ajCytfC2Xs1VMQlhsga8LQACMhY"], referer: https://www.softhubtechno.ehx.czu.mybluehostin.me/images/img/Admin/logo/images/Admin/logo/js/Admin/logo/images/clients/8.PNG
[Mon Jun 15 20:19:34.079411 2026] [security2:error] [pid 53359:tid 53570] [client 47.79.201.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "brainstrom.org"] [uri "/index.php"] [unique_id "ajCytfC2Xs1VMQlhsga8KwACX10"], referer: https://www.google.com/
[Mon Jun 15 20:19:34.156966 2026] [security2:error] [pid 53359:tid 53592] [client 20.229.212.220:54632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.212.229.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "archresource.co"] [uri "/atomlib.php"] [unique_id "ajCytvC2Xs1VMQlhsga8MQAAAnU"]
[Mon Jun 15 20:19:34.168556 2026] [security2:error] [pid 53359:tid 53374] [remote 103.127.30.137:47162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.30.127.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "swastiklandmark.com"] [uri "/wp-login.php"] [unique_id "ajCytvC2Xs1VMQlhsga8MgACQwg"]
[Mon Jun 15 20:19:34.185956 2026] [security2:error] [pid 53359:tid 53498] [client 103.125.146.57:37205] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/widgets/admin.php"] [unique_id "ajCytvC2Xs1VMQlhsga8NgAAAhc"]
[Mon Jun 15 20:19:34.286632 2026] [security2:error] [pid 53359:tid 53551] [client 57.141.14.40:26254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCytvC2Xs1VMQlhsga8MwACTG4"]
[Mon Jun 15 20:19:34.394652 2026] [security2:error] [pid 51003:tid 51144] [client 139.99.122.191:58408] ModSecurity: Access denied with code 406 (phase 1). Pattern match "xmlrpc\\\\.php" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "73"] [id "392331"] [rev "3"] [msg "Atomicorp.com WAF Rules: xmlrpc DOS attack"] [severity "CRITICAL"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCytspsKyvb75pkSvacuwAAAZo"]
[Mon Jun 15 20:19:34.394797 2026] [security2:error] [pid 51003:tid 51144] [client 139.99.122.191:58408] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCytspsKyvb75pkSvacuwAAAZo"]
[Mon Jun 15 20:19:34.408580 2026] [security2:error] [pid 53359:tid 53506] [client 139.99.122.191:58420] ModSecurity: Access denied with code 406 (phase 1). Pattern match "xmlrpc\\\\.php" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "73"] [id "392331"] [rev "3"] [msg "Atomicorp.com WAF Rules: xmlrpc DOS attack"] [severity "CRITICAL"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCytvC2Xs1VMQlhsga8QwAAAh8"]
[Mon Jun 15 20:19:34.408736 2026] [security2:error] [pid 53359:tid 53506] [client 139.99.122.191:58420] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCytvC2Xs1VMQlhsga8QwAAAh8"]
[Mon Jun 15 20:19:34.418717 2026] [security2:error] [pid 53359:tid 53590] [client 139.99.122.191:58404] ModSecurity: Access denied with code 406 (phase 1). Pattern match "xmlrpc\\\\.php" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "73"] [id "392331"] [rev "3"] [msg "Atomicorp.com WAF Rules: xmlrpc DOS attack"] [severity "CRITICAL"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCytvC2Xs1VMQlhsga8RAAAAnM"]
[Mon Jun 15 20:19:34.418867 2026] [security2:error] [pid 53359:tid 53590] [client 139.99.122.191:58404] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCytvC2Xs1VMQlhsga8RAAAAnM"]
[Mon Jun 15 20:19:34.420278 2026] [security2:error] [pid 53359:tid 53621] [client 139.99.122.191:58416] ModSecurity: Access denied with code 406 (phase 1). Pattern match "xmlrpc\\\\.php" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "73"] [id "392331"] [rev "3"] [msg "Atomicorp.com WAF Rules: xmlrpc DOS attack"] [severity "CRITICAL"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCytvC2Xs1VMQlhsga8RQAAApI"]
[Mon Jun 15 20:19:34.420394 2026] [security2:error] [pid 53359:tid 53621] [client 139.99.122.191:58416] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCytvC2Xs1VMQlhsga8RQAAApI"]
[Mon Jun 15 20:19:34.610269 2026] [security2:error] [pid 51003:tid 51218] [client 139.99.122.191:58430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.122.99.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srinivasgorthyandco.com"] [uri "/wp-login.php"] [unique_id "ajCytspsKyvb75pkSvacxAAAAeQ"]
[Mon Jun 15 20:19:34.616485 2026] [security2:error] [pid 53359:tid 53520] [client 103.125.146.41:44465] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/Requests/Utility/"] [unique_id "ajCytvC2Xs1VMQlhsga8SgAAAi0"]
[Mon Jun 15 20:19:34.654413 2026] [security2:error] [pid 53359:tid 53448] [remote 103.127.30.137:47162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.30.127.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "swastiklandmark.com"] [uri "/wp-login.php"] [unique_id "ajCytvC2Xs1VMQlhsga8SwACJVI"], referer: https://swastiklandmark.com/wp-login.php
[Mon Jun 15 20:19:34.988120 2026] [security2:error] [pid 53359:tid 53522] [client 20.229.212.220:55072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.212.229.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "archresource.co"] [uri "/fm.php"] [unique_id "ajCytvC2Xs1VMQlhsga8UwAAAi8"]
[Mon Jun 15 20:19:35.039922 2026] [security2:error] [pid 51003:tid 51227] [client 103.125.146.40:24401] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/random_compat/config.php"] [unique_id "ajCyt8psKyvb75pkSvaczwAAAe0"]
[Mon Jun 15 20:19:35.087753 2026] [security2:error] [pid 53359:tid 53442] [remote 210.211.99.176:57082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.99.211.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.npmassociate.com"] [uri "/wp-login.php"] [unique_id "ajCyt_C2Xs1VMQlhsga8VQACPkw"]
[Mon Jun 15 20:19:35.139887 2026] [security2:error] [pid 51003:tid 51176] [client 104.207.32.94:58471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.32.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rajunandkardeputycollector.blog"] [uri "/wp-login.php"] [unique_id "ajCyt8psKyvb75pkSvac0AAAAbo"], referer: https://rajunandkardeputycollector.blog/wp-login.php
[Mon Jun 15 20:19:35.384875 2026] [security2:error] [pid 51003:tid 51183] [client 126.209.47.75:61181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.47.209.126.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nxtal.com"] [uri "/xmlrpc.php"] [unique_id "ajCyt8psKyvb75pkSvac0gAAAcE"]
[Mon Jun 15 20:19:35.385012 2026] [security2:error] [pid 51003:tid 51183] [client 126.209.47.75:61181] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nxtal.com"] [uri "/xmlrpc.php"] [unique_id "ajCyt8psKyvb75pkSvac0gAAAcE"]
[Mon Jun 15 20:19:35.454306 2026] [security2:error] [pid 51003:tid 51193] [client 103.125.146.76:35253] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-admin/maint/config.php"] [unique_id "ajCyt8psKyvb75pkSvac1wAAAcs"]
[Mon Jun 15 20:19:35.474407 2026] [security2:error] [pid 51003:tid 51191] [client 107.189.2.75:49499] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jaywadhwa.com"] [uri "/index.php"] [unique_id "ajCytspsKyvb75pkSvacxQAAAck"], referer: http://www.google.com.hk
[Mon Jun 15 20:19:35.521773 2026] [security2:error] [pid 53359:tid 53406] [remote 210.211.99.176:57082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.99.211.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.npmassociate.com"] [uri "/wp-login.php"] [unique_id "ajCyt_C2Xs1VMQlhsga8YAACUig"], referer: https://mail.npmassociate.com/wp-login.php
[Mon Jun 15 20:19:35.558827 2026] [rewrite:error] [pid 51003:tid 51086] [remote 47.79.199.90:41708] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:19:35.766728 2026] [security2:error] [pid 51003:tid 51198] [client 20.229.212.220:55568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.212.229.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "archresource.co"] [uri "/themes.php"] [unique_id "ajCyt8psKyvb75pkSvac6wAAAdA"]
[Mon Jun 15 20:19:35.824008 2026] [rewrite:error] [pid 51003:tid 51120] [remote 47.79.199.90:41708] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:19:35.886799 2026] [security2:error] [pid 53359:tid 53519] [client 103.125.146.42:24633] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/images/wlw/admin.php"] [unique_id "ajCyt_C2Xs1VMQlhsga8ZwAAAiw"]
[Mon Jun 15 20:19:35.901824 2026] [security2:error] [pid 51003:tid 51199] [client 139.99.122.191:58514] ModSecurity: Access denied with code 406 (phase 1). Pattern match "xmlrpc\\\\.php" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "73"] [id "392331"] [rev "3"] [msg "Atomicorp.com WAF Rules: xmlrpc DOS attack"] [severity "CRITICAL"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCyt8psKyvb75pkSvac8AAAAdE"]
[Mon Jun 15 20:19:35.924172 2026] [security2:error] [pid 51003:tid 51224] [client 139.99.122.191:58526] ModSecurity: Access denied with code 406 (phase 1). Pattern match "xmlrpc\\\\.php" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "73"] [id "392331"] [rev "3"] [msg "Atomicorp.com WAF Rules: xmlrpc DOS attack"] [severity "CRITICAL"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCyt8psKyvb75pkSvac9AAAAeo"]
[Mon Jun 15 20:19:35.926517 2026] [security2:error] [pid 51003:tid 51224] [client 139.99.122.191:58526] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCyt8psKyvb75pkSvac9AAAAeo"]
[Mon Jun 15 20:19:35.929163 2026] [security2:error] [pid 51003:tid 51199] [client 139.99.122.191:58514] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCyt8psKyvb75pkSvac8AAAAdE"]
[Mon Jun 15 20:19:35.967151 2026] [security2:error] [pid 51003:tid 51139] [client 57.141.14.75:36096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyt8psKyvb75pkSvac7QABlTU"]
[Mon Jun 15 20:19:36.076151 2026] [security2:error] [pid 53359:tid 53567] [client 139.99.122.191:58558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.122.99.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srinivasgorthyandco.com"] [uri "/wp-login.php"] [unique_id "ajCyuPC2Xs1VMQlhsga8bwAAAlw"]
[Mon Jun 15 20:19:36.084906 2026] [security2:error] [pid 53359:tid 53517] [client 139.99.122.191:58552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.122.99.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srinivasgorthyandco.com"] [uri "/wp-login.php"] [unique_id "ajCyuPC2Xs1VMQlhsga8cAAAAio"]
[Mon Jun 15 20:19:36.135726 2026] [security2:error] [pid 53359:tid 53573] [client 66.249.79.75:53739] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "majividyarthikes.com"] [uri "/index.php"] [unique_id "ajCyt_C2Xs1VMQlhsga8ZgAAAmI"]
[Mon Jun 15 20:19:36.252084 2026] [security2:error] [pid 53359:tid 53590] [client 139.99.122.191:58564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.122.99.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srinivasgorthyandco.com"] [uri "/wp-login.php"] [unique_id "ajCyuPC2Xs1VMQlhsga8dAAAAnM"]
[Mon Jun 15 20:19:36.287849 2026] [security2:error] [pid 53359:tid 53543] [client 103.125.146.59:21361] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/Requests/admin.php"] [unique_id "ajCyuPC2Xs1VMQlhsga8dgAAAkQ"]
[Mon Jun 15 20:19:36.322909 2026] [security2:error] [pid 53359:tid 53539] [client 139.99.122.191:58556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.122.99.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srinivasgorthyandco.com"] [uri "/wp-login.php"] [unique_id "ajCyuPC2Xs1VMQlhsga8eAAAAkA"]
[Mon Jun 15 20:19:36.376911 2026] [security2:error] [pid 53359:tid 53497] [client 20.229.212.220:56104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.212.229.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "archresource.co"] [uri "/wp-blog.php"] [unique_id "ajCyuPC2Xs1VMQlhsga8eQAAAhY"]
[Mon Jun 15 20:19:36.718333 2026] [security2:error] [pid 53359:tid 53552] [client 103.125.146.53:61203] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/global.php"] [unique_id "ajCyuPC2Xs1VMQlhsga8iQAAAk0"]
[Mon Jun 15 20:19:36.830341 2026] [security2:error] [pid 51003:tid 51191] [client 18.118.31.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "burgerking-menu.com"] [uri "/index.php"] [unique_id "ajCyuMpsKyvb75pkSvadBAAAAck"]
[Mon Jun 15 20:19:36.940372 2026] [security2:error] [pid 53359:tid 53427] [remote 31.3.241.131:59672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.241.3.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "unitopaquacare.com"] [uri "/wp-login.php"] [unique_id "ajCyuPC2Xs1VMQlhsga8igACVj0"]
[Mon Jun 15 20:19:37.099417 2026] [security2:error] [pid 53359:tid 53398] [remote 31.3.241.131:59672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.241.3.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "unitopaquacare.com"] [uri "/wp-login.php"] [unique_id "ajCyufC2Xs1VMQlhsga8kQACUyA"], referer: https://unitopaquacare.com/wp-login.php
[Mon Jun 15 20:19:37.105634 2026] [security2:error] [pid 51003:tid 51197] [client 20.229.212.220:56638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.212.229.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "archresource.co"] [uri "/wp-the.php"] [unique_id "ajCyucpsKyvb75pkSvadEAAAAc8"]
[Mon Jun 15 20:19:37.187667 2026] [security2:error] [pid 53359:tid 53559] [client 65.111.30.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.procrastinatingworker.imcorp.in"] [uri "/index.php"] [unique_id "ajCyufC2Xs1VMQlhsga8jgAAAlQ"]
[Mon Jun 15 20:19:37.216061 2026] [security2:error] [pid 53359:tid 53622] [client 103.125.146.48:45695] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/wp-load.php"] [unique_id "ajCyufC2Xs1VMQlhsga8mwAAApM"]
[Mon Jun 15 20:19:37.346892 2026] [security2:error] [pid 53359:tid 53531] [client 18.118.31.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.burgerking-menu.com"] [uri "/index.php"] [unique_id "ajCyufC2Xs1VMQlhsga8mAAAAjg"], referer: https://burgerking-menu.com/burger-king-cheeseburger/
[Mon Jun 15 20:19:37.452207 2026] [security2:error] [pid 51003:tid 51245] [client 181.233.179.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kthemani.com"] [uri "/index.php"] [unique_id "ajCyt8psKyvb75pkSvac2wAAAf8"]
[Mon Jun 15 20:19:37.463416 2026] [security2:error] [pid 53359:tid 53615] [client 57.141.14.73:52400] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyufC2Xs1VMQlhsga8nAACjDI"]
[Mon Jun 15 20:19:37.606514 2026] [core:error] [pid 53359:tid 53540] [client 3.151.194.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jun 15 20:19:37.606537 2026] [core:error] [pid 53359:tid 53540] [client 3.151.194.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jun 15 20:19:37.621476 2026] [security2:error] [pid 53359:tid 53583] [client 103.125.146.80:45251] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/js/app.php"] [unique_id "ajCyufC2Xs1VMQlhsga8rQAAAmw"]
[Mon Jun 15 20:19:37.649402 2026] [rewrite:error] [pid 51003:tid 51097] [remote 47.79.198.145:30854] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:19:37.753941 2026] [security2:error] [pid 53359:tid 53477] [remote 2a03:2880:f806:10:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ruchini.hemani.finance"] [uri "/index.php"] [unique_id "ajCyufC2Xs1VMQlhsga8rAACSm8"]
[Mon Jun 15 20:19:37.862648 2026] [security2:error] [pid 51003:tid 51213] [client 139.99.122.191:58648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.122.99.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srinivasgorthyandco.com"] [uri "/wp-login.php"] [unique_id "ajCyucpsKyvb75pkSvadIQAAAd8"]
[Mon Jun 15 20:19:37.863083 2026] [security2:error] [pid 53359:tid 53514] [client 20.229.212.220:57172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.212.229.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "archresource.co"] [uri "/CDX2.php"] [unique_id "ajCyufC2Xs1VMQlhsga8sgAAAic"]
[Mon Jun 15 20:19:37.902951 2026] [rewrite:error] [pid 51003:tid 51070] [remote 47.79.198.145:30854] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:19:37.953538 2026] [security2:error] [pid 53359:tid 53525] [client 209.141.46.91:56002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.46.141.209.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandkare.com"] [uri "/wp-login.php"] [unique_id "ajCyufC2Xs1VMQlhsga8tAAAAjI"]
[Mon Jun 15 20:19:38.006074 2026] [security2:error] [pid 53359:tid 53541] [client 103.125.146.73:34199] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/random_compat/admin.php"] [unique_id "ajCyuvC2Xs1VMQlhsga8tgAAAkI"]
[Mon Jun 15 20:19:38.081754 2026] [security2:error] [pid 53359:tid 53412] [remote 47.128.119.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCyufC2Xs1VMQlhsga8pAACYi4"]
[Mon Jun 15 20:19:38.355305 2026] [security2:error] [pid 53359:tid 53596] [client 162.214.80.21:52440] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "talkmint.com"] [uri "/wp-content/uploads/2023/11/logo.png.webp"] [unique_id "ajCyuvC2Xs1VMQlhsga8vQAAAnk"]
[Mon Jun 15 20:19:38.376065 2026] [security2:error] [pid 53359:tid 53535] [client 162.214.80.21:52456] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "talkmint.com"] [uri "/wp-content/uploads/2023/11/footer-logo.png.webp"] [unique_id "ajCyuvC2Xs1VMQlhsga8vgAAAjw"]
[Mon Jun 15 20:19:38.389511 2026] [security2:error] [pid 53359:tid 53593] [client 103.125.146.55:47193] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/images/admin.php"] [unique_id "ajCyuvC2Xs1VMQlhsga8vwAAAnY"]
[Mon Jun 15 20:19:38.428263 2026] [security2:error] [pid 51003:tid 51187] [client 35.202.210.71:51223] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talkmint.com"] [uri "/index.php"] [unique_id "ajCyuspsKyvb75pkSvadMQAAAcU"]
[Mon Jun 15 20:19:38.594257 2026] [security2:error] [pid 53359:tid 53506] [client 20.229.212.220:57683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.212.229.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "archresource.co"] [uri "/profile.php"] [unique_id "ajCyuvC2Xs1VMQlhsga8xQAAAh8"]
[Mon Jun 15 20:19:38.614678 2026] [fcgid:warn] [pid 51003:tid 51147] (70014)End of file found: [client 157.245.201.21:56514] mod_fcgid: can't get data from http client
[Mon Jun 15 20:19:38.671824 2026] [security2:error] [pid 51003:tid 51179] [client 31.219.209.201:56073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.209.219.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCyuspsKyvb75pkSvadQgAAAb0"]
[Mon Jun 15 20:19:38.671965 2026] [security2:error] [pid 51003:tid 51179] [client 31.219.209.201:56073] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCyuspsKyvb75pkSvadQgAAAb0"]
[Mon Jun 15 20:19:38.688358 2026] [fcgid:warn] [pid 51003:tid 51219] (70014)End of file found: [client 157.245.201.21:56528] mod_fcgid: can't get data from http client
[Mon Jun 15 20:19:38.791803 2026] [security2:error] [pid 53359:tid 53520] [client 47.79.205.209:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "designhub1610.com"] [uri "/index.php"] [unique_id "ajCyuvC2Xs1VMQlhsga8xAACLXw"], referer: https://www.google.com/
[Mon Jun 15 20:19:38.813781 2026] [security2:error] [pid 51003:tid 51248] [client 103.125.146.75:32157] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/certificates/login.php"] [unique_id "ajCyuspsKyvb75pkSvadRQAAAgI"]
[Mon Jun 15 20:19:38.831147 2026] [rewrite:error] [pid 53359:tid 53539] [client 47.79.198.74:38756] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:19:39.043938 2026] [security2:error] [pid 53359:tid 53576] [client 57.141.14.107:23573] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyuvC2Xs1VMQlhsga8zwACZXo"]
[Mon Jun 15 20:19:39.142027 2026] [security2:error] [pid 53359:tid 53499] [client 139.99.122.191:58640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.122.99.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srinivasgorthyandco.com"] [uri "/wp-login.php"] [unique_id "ajCyu_C2Xs1VMQlhsga83wAAAhg"]
[Mon Jun 15 20:19:39.213135 2026] [security2:error] [pid 53359:tid 53557] [client 103.163.220.5:39651] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/js/crop/config.php"] [unique_id "ajCyu_C2Xs1VMQlhsga85QAAAlI"]
[Mon Jun 15 20:19:39.286782 2026] [rewrite:error] [pid 53359:tid 53558] [client 47.79.198.74:38756] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:19:39.389195 2026] [security2:error] [pid 51003:tid 51131] [remote 57.141.14.73:52406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.14.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wilsonoverseas.com"] [uri "/items/K414993537"] [unique_id "ajCyu8psKyvb75pkSvadVwAB4H8"]
[Mon Jun 15 20:19:39.430642 2026] [security2:error] [pid 51003:tid 51227] [client 47.128.119.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCyuspsKyvb75pkSvadRwAB7Tg"], referer: https://mywordsnthoughts.com/myworld/tag/nutmeg-mace/
[Mon Jun 15 20:19:39.457739 2026] [security2:error] [pid 51003:tid 51240] [client 47.128.119.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCyuspsKyvb75pkSvadSAAB-hA"], referer: https://mywordsnthoughts.com/myworld/tag/nutmeg-mace/
[Mon Jun 15 20:19:39.554217 2026] [security2:error] [pid 53359:tid 53504] [client 20.229.212.220:58333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.212.229.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "archresource.co"] [uri "/wp-content/themes/admin.php"] [unique_id "ajCyu_C2Xs1VMQlhsga87QAAAh0"]
[Mon Jun 15 20:19:39.614603 2026] [security2:error] [pid 51003:tid 51243] [client 103.125.146.64:37099] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/well-known/"] [unique_id "ajCyu8psKyvb75pkSvadXAAAAf0"]
[Mon Jun 15 20:19:39.999421 2026] [security2:error] [pid 51003:tid 51141] [client 103.125.146.74:63195] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-admin/includes/config.php"] [unique_id "ajCyu8psKyvb75pkSvadZAAAAZc"]
[Mon Jun 15 20:19:40.094040 2026] [rewrite:error] [pid 51003:tid 51035] [remote 47.79.198.208:23210] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:19:40.375437 2026] [security2:error] [pid 51003:tid 51247] [client 20.229.212.220:59081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.212.229.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "archresource.co"] [uri "/ws80.php"] [unique_id "ajCyvMpsKyvb75pkSvadbgAAAgE"]
[Mon Jun 15 20:19:40.386247 2026] [rewrite:error] [pid 51003:tid 51028] [remote 47.79.198.208:23210] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:19:40.391836 2026] [security2:error] [pid 53359:tid 53608] [client 103.125.146.41:64787] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/certificates/config.php"] [unique_id "ajCyvPC2Xs1VMQlhsga9BwAAAoU"]
[Mon Jun 15 20:19:40.459877 2026] [security2:error] [pid 53359:tid 53452] [remote 74.7.242.26:40164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.242.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dnyanmudra.ehx.czu.mybluehostin.me"] [uri "/fonts/assets/js/images/home/images/home/slider/result.php"] [unique_id "ajCyvPC2Xs1VMQlhsga9DAACblY"], referer: https://dnyanmudra.ehx.czu.mybluehostin.me/fonts/assets/js/images/home/images/home/slider/s2.jpeg
[Mon Jun 15 20:19:40.470870 2026] [rewrite:error] [pid 51003:tid 51168] [client 47.79.199.110:4710] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:19:40.496247 2026] [rewrite:error] [pid 51003:tid 51157] [client 47.79.197.66:2252] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:19:40.561085 2026] [security2:error] [pid 53359:tid 53532] [client 57.141.14.14:25332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyvPC2Xs1VMQlhsga9CAACOV8"]
[Mon Jun 15 20:19:40.697051 2026] [security2:error] [pid 51003:tid 51238] [client 49.47.129.38:37230] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gpgaya.org"] [uri "/Admin/index.php"] [unique_id "ajCyvMpsKyvb75pkSvaddgAB-DM"], referer: https://www.gpgaya.org/
[Mon Jun 15 20:19:40.820083 2026] [security2:error] [pid 53359:tid 53584] [client 103.125.146.73:61963] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/settings.php"] [unique_id "ajCyvPC2Xs1VMQlhsga9KgAAAm0"]
[Mon Jun 15 20:19:40.873237 2026] [security2:error] [pid 53359:tid 53507] [client 139.99.122.191:58856] ModSecurity: Access denied with code 406 (phase 1). Pattern match "xmlrpc\\\\.php" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "73"] [id "392331"] [rev "3"] [msg "Atomicorp.com WAF Rules: xmlrpc DOS attack"] [severity "CRITICAL"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCyvPC2Xs1VMQlhsga9LAAAAiA"]
[Mon Jun 15 20:19:40.873386 2026] [security2:error] [pid 53359:tid 53507] [client 139.99.122.191:58856] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCyvPC2Xs1VMQlhsga9LAAAAiA"]
[Mon Jun 15 20:19:40.937530 2026] [rewrite:error] [pid 51003:tid 51191] [client 47.79.199.110:4710] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:19:40.955173 2026] [rewrite:error] [pid 51003:tid 51155] [client 47.79.197.66:2252] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:19:41.027307 2026] [security2:error] [pid 53359:tid 53563] [client 200.110.207.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kthemani.com"] [uri "/index.php"] [unique_id "ajCyuvC2Xs1VMQlhsga80AACWFE"]
[Mon Jun 15 20:19:41.123054 2026] [security2:error] [pid 53359:tid 53590] [client 20.229.212.220:59676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.212.229.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "archresource.co"] [uri "/403.php"] [unique_id "ajCyvfC2Xs1VMQlhsga9NAAAAnM"]
[Mon Jun 15 20:19:41.207728 2026] [security2:error] [pid 51003:tid 51249] [client 49.47.129.38:37230] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gpgaya.org"] [uri "/index.php"] [unique_id "ajCyvcpsKyvb75pkSvadgwACAxI"], referer: https://gpgaya.org/assets/lib/owl-carousel/owl-carousel.css
[Mon Jun 15 20:19:41.218890 2026] [security2:error] [pid 53359:tid 53526] [client 103.125.146.69:21295] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/common.php"] [unique_id "ajCyvfC2Xs1VMQlhsga9NwAAAjM"]
[Mon Jun 15 20:19:41.225496 2026] [security2:error] [pid 51003:tid 51200] [client 49.47.129.38:37230] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gpgaya.org"] [uri "/Admin/index.php"] [unique_id "ajCyvcpsKyvb75pkSvadhAAB0l8"], referer: https://www.gpgaya.org/
[Mon Jun 15 20:19:41.373015 2026] [security2:error] [pid 53359:tid 53506] [client 65.111.30.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.procrastinatingworker.imcorp.in"] [uri "/index.php"] [unique_id "ajCyvfC2Xs1VMQlhsga9PQAAAh8"]
[Mon Jun 15 20:19:41.528964 2026] [security2:error] [pid 51003:tid 51162] [client 49.37.157.202:60874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "desidelightmp.com"] [uri "/xmlrpc.php"] [unique_id "ajCyvcpsKyvb75pkSvadkAAAAaw"]
[Mon Jun 15 20:19:41.529058 2026] [security2:error] [pid 51003:tid 51162] [client 49.37.157.202:60874] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "desidelightmp.com"] [uri "/xmlrpc.php"] [unique_id "ajCyvcpsKyvb75pkSvadkAAAAaw"]
[Mon Jun 15 20:19:41.562687 2026] [security2:error] [pid 51003:tid 51192] [client 157.55.39.6:63686] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ybsolutions.in"] [uri "/index.php"] [unique_id "ajCyvcpsKyvb75pkSvadkQABykQ"]
[Mon Jun 15 20:19:41.587403 2026] [security2:error] [pid 51003:tid 51202] [client 103.125.146.41:51653] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/images/wp-load.php"] [unique_id "ajCyvcpsKyvb75pkSvadlgAAAdQ"]
[Mon Jun 15 20:19:41.712671 2026] [rewrite:error] [pid 53359:tid 53608] [client 47.79.198.30:3160] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:19:41.765952 2026] [security2:error] [pid 51003:tid 51233] [client 139.99.122.191:59036] ModSecurity: Access denied with code 406 (phase 1). Pattern match "xmlrpc\\\\.php" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "73"] [id "392331"] [rev "3"] [msg "Atomicorp.com WAF Rules: xmlrpc DOS attack"] [severity "CRITICAL"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCyvcpsKyvb75pkSvadmQAAAfM"]
[Mon Jun 15 20:19:41.766083 2026] [security2:error] [pid 51003:tid 51233] [client 139.99.122.191:59036] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCyvcpsKyvb75pkSvadmQAAAfM"]
[Mon Jun 15 20:19:41.787650 2026] [security2:error] [pid 53359:tid 53594] [client 139.99.122.191:59020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.122.99.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srinivasgorthyandco.com"] [uri "/wp-login.php"] [unique_id "ajCyvfC2Xs1VMQlhsga9UQAAAnc"]
[Mon Jun 15 20:19:41.826165 2026] [rewrite:error] [pid 51003:tid 51021] [remote 47.79.198.90:27892] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:19:41.999671 2026] [security2:error] [pid 51003:tid 51167] [client 103.125.146.64:50223] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/js/admin.php"] [unique_id "ajCyvcpsKyvb75pkSvadoQAAAbE"]
[Mon Jun 15 20:19:42.094313 2026] [rewrite:error] [pid 51003:tid 51068] [remote 47.79.198.90:27892] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:19:42.176229 2026] [rewrite:error] [pid 53359:tid 53525] [client 47.79.198.30:3160] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:19:42.294502 2026] [security2:error] [pid 51003:tid 51122] [remote 57.141.14.34:22152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyvspsKyvb75pkSvadpwAB4nY"]
[Mon Jun 15 20:19:42.363948 2026] [rewrite:error] [pid 51003:tid 51128] [remote 47.79.198.102:14606] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:19:42.434986 2026] [security2:error] [pid 53359:tid 53565] [client 103.125.146.46:52553] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/init.php"] [unique_id "ajCyvvC2Xs1VMQlhsga9aAAAAlo"]
[Mon Jun 15 20:19:42.470044 2026] [security2:error] [pid 53359:tid 53505] [client 82.102.18.190:52590] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.persnofinance.com"] [uri "/autodiscover/autodiscover.xml/wp-includes/wlwmanifest.xml"] [unique_id "ajCyvvC2Xs1VMQlhsga9bAAAAh4"]
[Mon Jun 15 20:19:42.644115 2026] [rewrite:error] [pid 51003:tid 51058] [remote 47.79.198.102:14606] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:19:42.797618 2026] [autoindex:error] [pid 51003:tid 51235] [client 192.71.142.40:0] AH01276: Cannot serve directory /home4/pytndcmy/public_html/mrrhealthtech.us/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://mrrhealthtech.us/
[Mon Jun 15 20:19:42.822115 2026] [security2:error] [pid 53359:tid 53580] [client 20.229.212.220:60217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.212.229.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "archresource.co"] [uri "/a4.php"] [unique_id "ajCyvvC2Xs1VMQlhsga9dwAAAmk"]
[Mon Jun 15 20:19:42.852183 2026] [security2:error] [pid 53359:tid 53536] [client 103.125.146.77:38953] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/uploads/redux/config.php"] [unique_id "ajCyvvC2Xs1VMQlhsga9eQAAAj0"]
[Mon Jun 15 20:19:42.861207 2026] [security2:error] [pid 51003:tid 51199] [client 192.140.64.94:29973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.64.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCyvspsKyvb75pkSvaduQAAAdE"]
[Mon Jun 15 20:19:42.861296 2026] [security2:error] [pid 51003:tid 51199] [client 192.140.64.94:29973] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCyvspsKyvb75pkSvaduQAAAdE"]
[Mon Jun 15 20:19:43.007387 2026] [rewrite:error] [pid 53359:tid 53414] [remote 47.79.198.183:47544] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:19:43.260843 2026] [rewrite:error] [pid 53359:tid 53382] [remote 47.79.198.183:47544] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:19:43.291831 2026] [security2:error] [pid 53359:tid 53525] [client 103.125.146.71:51867] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/images/settings.php"] [unique_id "ajCyv_C2Xs1VMQlhsga9jAAAAjI"]
[Mon Jun 15 20:19:43.411261 2026] [security2:error] [pid 53359:tid 53499] [client 57.141.14.100:21113] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyv_C2Xs1VMQlhsga9jQACGAs"]
[Mon Jun 15 20:19:43.422938 2026] [security2:error] [pid 51003:tid 51255] [client 20.229.212.220:60818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.212.229.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "archresource.co"] [uri "/app.php"] [unique_id "ajCyv8psKyvb75pkSvadxAAAAgk"]
[Mon Jun 15 20:19:43.707603 2026] [security2:error] [pid 53359:tid 53530] [client 103.125.146.47:53791] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/blocks/admin.php"] [unique_id "ajCyv_C2Xs1VMQlhsga9mAAAAjc"]
[Mon Jun 15 20:19:43.817001 2026] [rewrite:error] [pid 53359:tid 53424] [remote 47.79.199.34:12198] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:19:43.951805 2026] [security2:error] [pid 53359:tid 53431] [remote 64.131.86.2:58222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.86.131.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sabaarthouse.com"] [uri "/wp-login.php"] [unique_id "ajCyv_C2Xs1VMQlhsga9oAACHEE"]
[Mon Jun 15 20:19:44.017338 2026] [security2:error] [pid 53359:tid 53587] [client 27.61.160.173:6519] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ahk.kavadevelopers.com"] [uri "/public/index.php"] [unique_id "ajCyv_C2Xs1VMQlhsga9nQACcAA"], referer: https://ahk.kavadevelopers.com/public/admin/login
[Mon Jun 15 20:19:44.042558 2026] [rewrite:error] [pid 53359:tid 53425] [remote 47.79.197.80:30024] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:19:44.087921 2026] [rewrite:error] [pid 53359:tid 53474] [remote 47.79.199.34:12198] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:19:44.096345 2026] [security2:error] [pid 53359:tid 53581] [client 103.125.146.64:51721] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/js/init.php"] [unique_id "ajCywPC2Xs1VMQlhsga9pgAAAmo"]
[Mon Jun 15 20:19:44.194883 2026] [security2:error] [pid 53359:tid 53506] [client 20.229.212.220:61240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.212.229.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "archresource.co"] [uri "/buy.php"] [unique_id "ajCywPC2Xs1VMQlhsga9qgAAAh8"]
[Mon Jun 15 20:19:44.225931 2026] [security2:error] [pid 53359:tid 53388] [remote 64.131.86.2:58222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.86.131.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sabaarthouse.com"] [uri "/wp-login.php"] [unique_id "ajCywPC2Xs1VMQlhsga9qwACXxY"], referer: https://sabaarthouse.com/wp-login.php
[Mon Jun 15 20:19:44.290643 2026] [security2:error] [pid 51003:tid 51152] [client 57.141.14.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aarohiarts.org"] [uri "/index.php"] [unique_id "ajCywMpsKyvb75pkSvadzwAAAaI"]
[Mon Jun 15 20:19:44.306397 2026] [rewrite:error] [pid 53359:tid 53459] [remote 47.79.197.80:30024] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:19:44.399844 2026] [security2:error] [pid 51003:tid 51059] [remote 47.128.119.118:38262] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.api-markets.com"] [uri "/robots.txt"] [unique_id "ajCywMpsKyvb75pkSvad2AACBTc"]
[Mon Jun 15 20:19:44.488455 2026] [security2:error] [pid 51003:tid 51174] [client 103.125.146.78:47103] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/images/login.php"] [unique_id "ajCywMpsKyvb75pkSvad3gAAAbg"]
[Mon Jun 15 20:19:44.505912 2026] [rewrite:error] [pid 53359:tid 53492] [remote 47.79.197.35:64810] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:19:44.665368 2026] [security2:error] [pid 53359:tid 53421] [remote 213.171.208.62:51734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.208.171.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "symcon.in"] [uri "/wp-login.php"] [unique_id "ajCywPC2Xs1VMQlhsga9uAACZDc"]
[Mon Jun 15 20:19:44.716267 2026] [security2:error] [pid 51003:tid 51232] [client 139.99.122.191:59190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.122.99.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srinivasgorthyandco.com"] [uri "/wp-login.php"] [unique_id "ajCywMpsKyvb75pkSvad5AAAAfI"]
[Mon Jun 15 20:19:44.764211 2026] [rewrite:error] [pid 53359:tid 53476] [remote 47.79.197.35:64810] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:19:44.845476 2026] [security2:error] [pid 53359:tid 53534] [client 187.245.103.92:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kthemani.com"] [uri "/index.php"] [unique_id "ajCyvvC2Xs1VMQlhsga9ggAAAjs"]
[Mon Jun 15 20:19:44.861369 2026] [security2:error] [pid 51003:tid 51235] [client 104.207.34.209:46419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.34.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rajunandkardeputycollector.blog"] [uri "/wp-login.php"] [unique_id "ajCywMpsKyvb75pkSvad5wAAAfU"], referer: https://rajunandkardeputycollector.blog/wp-login.php
[Mon Jun 15 20:19:44.947850 2026] [security2:error] [pid 51003:tid 51151] [client 82.102.18.190:52592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.persnofinance.com"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "ajCywMpsKyvb75pkSvad7AAAAaE"]
[Mon Jun 15 20:19:45.003107 2026] [security2:error] [pid 53359:tid 53531] [client 65.111.30.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.procrastinatingworker.imcorp.in"] [uri "/index.php"] [unique_id "ajCywPC2Xs1VMQlhsga9wAAAAjg"]
[Mon Jun 15 20:19:45.004401 2026] [security2:error] [pid 53359:tid 53499] [client 20.229.212.220:61714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.212.229.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "archresource.co"] [uri "/core.php"] [unique_id "ajCywfC2Xs1VMQlhsga9wwAAAhg"]
[Mon Jun 15 20:19:45.020267 2026] [security2:error] [pid 53359:tid 53569] [client 103.125.146.31:33523] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/uploads/redux/"] [unique_id "ajCywfC2Xs1VMQlhsga9xgAAAl4"]
[Mon Jun 15 20:19:45.071583 2026] [security2:error] [pid 53359:tid 53565] [client 57.141.14.44:37353] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCywPC2Xs1VMQlhsga9wgACWlI"]
[Mon Jun 15 20:19:45.177430 2026] [rewrite:error] [pid 53359:tid 53371] [remote 47.79.198.35:31482] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:19:45.194774 2026] [security2:error] [pid 51003:tid 51212] [client 34.178.228.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bloggermint.com"] [uri "/index.php"] [unique_id "ajCywcpsKyvb75pkSvad8gAAAd4"]
[Mon Jun 15 20:19:45.362188 2026] [security2:error] [pid 53359:tid 53466] [remote 74.7.227.149:57726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.shreeramsweets-co-in.xgh.ggk.mybluehostin.me"] [uri "/plugins/bootstrap/js/js/images_scroller/index.php"] [unique_id "ajCywfC2Xs1VMQlhsga96gACdWQ"], referer: https://www.shreeramsweets-co-in.xgh.ggk.mybluehostin.me/plugins/bootstrap/js/js/images_scroller/banner1.jpg
[Mon Jun 15 20:19:45.421679 2026] [security2:error] [pid 53359:tid 53496] [client 103.125.146.48:21915] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/uploads/2021/10/"] [unique_id "ajCywfC2Xs1VMQlhsga98AAAAhU"]
[Mon Jun 15 20:19:45.437422 2026] [rewrite:error] [pid 53359:tid 53482] [remote 47.79.198.35:31482] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:19:45.630639 2026] [security2:error] [pid 51003:tid 51165] [client 139.99.122.191:59308] ModSecurity: Access denied with code 406 (phase 1). Pattern match "xmlrpc\\\\.php" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "73"] [id "392331"] [rev "3"] [msg "Atomicorp.com WAF Rules: xmlrpc DOS attack"] [severity "CRITICAL"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCywcpsKyvb75pkSvaeAwAAAa8"]
[Mon Jun 15 20:19:45.630742 2026] [security2:error] [pid 51003:tid 51165] [client 139.99.122.191:59308] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCywcpsKyvb75pkSvaeAwAAAa8"]
[Mon Jun 15 20:19:45.645801 2026] [security2:error] [pid 53359:tid 53375] [remote 31.3.241.131:59686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.241.3.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sahilpatro.com"] [uri "/wp-login.php"] [unique_id "ajCywfC2Xs1VMQlhsga-BgACXQk"]
[Mon Jun 15 20:19:45.806088 2026] [security2:error] [pid 53359:tid 53570] [client 103.125.146.32:26591] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/theme-compat/theme-compat/config.php"] [unique_id "ajCywfC2Xs1VMQlhsga-EQAAAl8"]
[Mon Jun 15 20:19:45.811724 2026] [security2:error] [pid 53359:tid 53412] [remote 31.3.241.131:59686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.241.3.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sahilpatro.com"] [uri "/wp-login.php"] [unique_id "ajCywfC2Xs1VMQlhsga-EAACVi4"], referer: https://sahilpatro.com/wp-login.php
[Mon Jun 15 20:19:45.835946 2026] [security2:error] [pid 51003:tid 51069] [remote 111.225.148.5:62918] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sports-window.com"] [uri "/product/head-pct-pro-elite-tennis-racquet"] [unique_id "ajCywcpsKyvb75pkSvaeCAACBUE"]
[Mon Jun 15 20:19:45.866368 2026] [security2:error] [pid 53359:tid 53391] [remote 213.171.208.62:51734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.208.171.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "symcon.in"] [uri "/wp-login.php"] [unique_id "ajCywfC2Xs1VMQlhsga-EwACMBk"], referer: https://symcon.in/wp-login.php
[Mon Jun 15 20:19:45.890580 2026] [security2:error] [pid 51003:tid 51211] [client 20.229.212.220:62331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.212.229.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "archresource.co"] [uri "/lock360.php"] [unique_id "ajCywcpsKyvb75pkSvaeCgAAAd0"]
[Mon Jun 15 20:19:45.928913 2026] [rewrite:error] [pid 51003:tid 51077] [remote 47.79.199.31:18448] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:19:46.161108 2026] [rewrite:error] [pid 53359:tid 53396] [remote 47.79.199.105:34784] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:19:46.182465 2026] [rewrite:error] [pid 51003:tid 51053] [remote 47.79.199.31:18448] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:19:46.221531 2026] [security2:error] [pid 53359:tid 53532] [client 103.125.146.58:40651] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/images/config.php"] [unique_id "ajCywvC2Xs1VMQlhsga-PgAAAjk"]
[Mon Jun 15 20:19:46.298149 2026] [security2:error] [pid 51003:tid 51044] [remote 57.141.14.73:57174] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCywspsKyvb75pkSvaeEQABsCg"]
[Mon Jun 15 20:19:46.423133 2026] [rewrite:error] [pid 53359:tid 53443] [remote 47.79.199.105:34784] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:19:46.621253 2026] [security2:error] [pid 53359:tid 53542] [client 20.229.212.220:62771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.212.229.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "archresource.co"] [uri "/wp-block.php"] [unique_id "ajCywvC2Xs1VMQlhsga-VQAAAkM"]
[Mon Jun 15 20:19:46.653729 2026] [security2:error] [pid 51003:tid 51171] [client 103.125.146.67:61217] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/theme-compat/theme-compat/admin.php"] [unique_id "ajCywspsKyvb75pkSvaeGQAAAbU"]
[Mon Jun 15 20:19:46.832068 2026] [security2:error] [pid 53359:tid 53381] [remote 203.190.11.3:47646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.11.190.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextgenuniversity.us"] [uri "/wp-login.php"] [unique_id "ajCywvC2Xs1VMQlhsga-WgACeA8"]
[Mon Jun 15 20:19:47.043048 2026] [security2:error] [pid 53359:tid 53414] [remote 91.146.102.43:38446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.102.146.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vinayghanekar.com"] [uri "/wp-login.php"] [unique_id "ajCyw_C2Xs1VMQlhsga-ZwACUDA"]
[Mon Jun 15 20:19:47.097667 2026] [security2:error] [pid 53359:tid 53588] [client 196.113.208.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "studioforge.in"] [uri "/index.php"] [unique_id "ajCywvC2Xs1VMQlhsga-YAAAAnE"]
[Mon Jun 15 20:19:47.098470 2026] [security2:error] [pid 53359:tid 53503] [client 103.125.146.35:25667] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/certificates/admin.php"] [unique_id "ajCyw_C2Xs1VMQlhsga-awAAAhw"]
[Mon Jun 15 20:19:47.220388 2026] [security2:error] [pid 51003:tid 51105] [remote 31.3.241.131:50548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.241.3.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taciturban.net.in"] [uri "/wp-login.php"] [unique_id "ajCyw8psKyvb75pkSvaeLQABn2U"]
[Mon Jun 15 20:19:47.271965 2026] [security2:error] [pid 51003:tid 51162] [client 20.229.212.220:63312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.212.229.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "archresource.co"] [uri "/wp-content/admin.php"] [unique_id "ajCyw8psKyvb75pkSvaeLgAAAaw"]
[Mon Jun 15 20:19:47.274342 2026] [security2:error] [pid 53359:tid 53576] [client 46.138.25.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kthemani.com"] [uri "/index.php"] [unique_id "ajCywfC2Xs1VMQlhsga97QACZSQ"]
[Mon Jun 15 20:19:47.322705 2026] [security2:error] [pid 53359:tid 53489] [remote 91.146.102.43:38446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.102.146.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vinayghanekar.com"] [uri "/wp-login.php"] [unique_id "ajCyw_C2Xs1VMQlhsga-bQACkns"], referer: https://vinayghanekar.com/wp-login.php
[Mon Jun 15 20:19:47.353262 2026] [security2:error] [pid 53359:tid 53382] [remote 203.190.11.3:47646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.11.190.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextgenuniversity.us"] [uri "/wp-login.php"] [unique_id "ajCyw_C2Xs1VMQlhsga-bgACjxA"], referer: https://nextgenuniversity.us/wp-login.php
[Mon Jun 15 20:19:47.395934 2026] [security2:error] [pid 51003:tid 51036] [remote 31.3.241.131:50548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.241.3.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taciturban.net.in"] [uri "/wp-login.php"] [unique_id "ajCyw8psKyvb75pkSvaeLwAB6yA"], referer: https://taciturban.net.in/wp-login.php
[Mon Jun 15 20:19:47.466980 2026] [security2:error] [pid 53359:tid 53614] [client 57.141.14.82:40114] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyw_C2Xs1VMQlhsga-bwACixE"]
[Mon Jun 15 20:19:47.551295 2026] [security2:error] [pid 51003:tid 51183] [client 103.125.146.75:50179] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/SimplePie/Decode/config.php"] [unique_id "ajCyw8psKyvb75pkSvaeNgAAAcE"]
[Mon Jun 15 20:19:47.592994 2026] [rewrite:error] [pid 51003:tid 51050] [remote 47.79.197.240:59714] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:19:47.652194 2026] [security2:error] [pid 53359:tid 53549] [client 139.99.122.191:59402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.122.99.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srinivasgorthyandco.com"] [uri "/wp-login.php"] [unique_id "ajCyw_C2Xs1VMQlhsga-fwAAAko"]
[Mon Jun 15 20:19:47.678076 2026] [security2:error] [pid 53359:tid 53511] [client 82.102.18.190:52600] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.persnofinance.com"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "ajCyw_C2Xs1VMQlhsga-gAAAAiQ"]
[Mon Jun 15 20:19:47.699984 2026] [security2:error] [pid 51003:tid 51179] [client 52.167.144.217:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hemani.finance"] [uri "/index.php"] [unique_id "ajCyw8psKyvb75pkSvaeMQAAAb0"]
[Mon Jun 15 20:19:47.800238 2026] [security2:error] [pid 53359:tid 53579] [client 84.21.190.140:16304] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "tajbeautysalon.com.au"] [uri "/wp-content/plugins/mainwp-child/readme.txt"] [unique_id "ajCyw_C2Xs1VMQlhsga-iAAAAmg"]
[Mon Jun 15 20:19:47.851957 2026] [rewrite:error] [pid 51003:tid 51075] [remote 47.79.197.240:59714] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:19:48.025893 2026] [rewrite:error] [pid 53359:tid 53373] [remote 47.79.197.42:45972] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:19:48.039983 2026] [security2:error] [pid 51003:tid 51153] [client 20.229.212.220:63755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.212.229.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "archresource.co"] [uri "/wp-includes/assets/index.php"] [unique_id "ajCyxMpsKyvb75pkSvaeRQAAAaM"]
[Mon Jun 15 20:19:48.275932 2026] [rewrite:error] [pid 53359:tid 53453] [remote 47.79.197.42:45972] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:19:48.638633 2026] [security2:error] [pid 51003:tid 51045] [remote 74.7.243.230:39116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shreeramsweets-co-in.xgh.ggk.mybluehostin.me"] [uri "/plugins/owl-carousel/js/css/plugins/lightgallery/js/images/plugins/rangeslider/contact.php"] [unique_id "ajCyxMpsKyvb75pkSvaeWgAB0Sk"], referer: https://shreeramsweets-co-in.xgh.ggk.mybluehostin.me/plugins/owl-carousel/js/css/plugins/lightgallery/js/images/plugins/rangeslider/rangeslider.js
[Mon Jun 15 20:19:48.681360 2026] [security2:error] [pid 53359:tid 53569] [client 82.102.18.190:52614] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.persnofinance.com"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "ajCyxPC2Xs1VMQlhsga-owAAAl4"]
[Mon Jun 15 20:19:48.831114 2026] [security2:error] [pid 53359:tid 53422] [remote 185.55.229.75:59086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.229.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bongapetit.com"] [uri "/wp-login.php"] [unique_id "ajCyxPC2Xs1VMQlhsga-qwACHDg"]
[Mon Jun 15 20:19:48.911404 2026] [security2:error] [pid 51003:tid 51054] [remote 188.166.231.216:59638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.231.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arkinrubbers.com"] [uri "/wp-login.php"] [unique_id "ajCyxMpsKyvb75pkSvaebwAB8jI"]
[Mon Jun 15 20:19:48.965825 2026] [security2:error] [pid 53359:tid 53614] [client 57.141.14.112:21156] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyxPC2Xs1VMQlhsga-rQACi0M"]
[Mon Jun 15 20:19:48.970870 2026] [security2:error] [pid 53359:tid 53570] [client 20.229.212.220:64328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.212.229.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "archresource.co"] [uri "/wp-includes/images/wp-login.php"] [unique_id "ajCyxPC2Xs1VMQlhsga-rwAAAl8"]
[Mon Jun 15 20:19:48.995776 2026] [security2:error] [pid 53359:tid 53514] [client 103.125.146.66:45931] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/app.php"] [unique_id "ajCyxPC2Xs1VMQlhsga-sQAAAic"]
[Mon Jun 15 20:19:49.038017 2026] [security2:error] [pid 53359:tid 53379] [remote 216.73.217.151:10941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wilsonoverseas.com"] [uri "/"] [unique_id "ajCyxfC2Xs1VMQlhsga-sgACfw0"]
[Mon Jun 15 20:19:49.093940 2026] [security2:error] [pid 53359:tid 53450] [remote 185.55.229.75:59086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.229.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bongapetit.com"] [uri "/wp-login.php"] [unique_id "ajCyxfC2Xs1VMQlhsga-swACWVQ"], referer: https://bongapetit.com/wp-login.php
[Mon Jun 15 20:19:49.154413 2026] [security2:error] [pid 53359:tid 53385] [remote 162.254.36.150:59890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.36.254.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mirrorbuzz.com"] [uri "/wp-login.php"] [unique_id "ajCyxfC2Xs1VMQlhsga-tAACfhM"]
[Mon Jun 15 20:19:49.163195 2026] [security2:error] [pid 51003:tid 51092] [remote 114.119.130.177:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.fashionsfever.com"] [uri "/wp-admin/admin.php"] [unique_id "ajCyxcpsKyvb75pkSvaedQAB21g"], referer: https://www.fashionsfever.com/
[Mon Jun 15 20:19:49.229407 2026] [security2:error] [pid 53359:tid 53538] [client 31.219.209.201:56681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.209.219.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCyxfC2Xs1VMQlhsga-twAAAj8"]
[Mon Jun 15 20:19:49.229522 2026] [security2:error] [pid 53359:tid 53538] [client 31.219.209.201:56681] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCyxfC2Xs1VMQlhsga-twAAAj8"]
[Mon Jun 15 20:19:49.276584 2026] [security2:error] [pid 53359:tid 53554] [client 139.99.122.191:59500] ModSecurity: Access denied with code 406 (phase 1). Pattern match "xmlrpc\\\\.php" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "73"] [id "392331"] [rev "3"] [msg "Atomicorp.com WAF Rules: xmlrpc DOS attack"] [severity "CRITICAL"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCyxfC2Xs1VMQlhsga-uwAAAk8"]
[Mon Jun 15 20:19:49.276700 2026] [security2:error] [pid 53359:tid 53554] [client 139.99.122.191:59500] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCyxfC2Xs1VMQlhsga-uwAAAk8"]
[Mon Jun 15 20:19:49.298517 2026] [security2:error] [pid 51003:tid 51062] [remote 188.166.231.216:59638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.231.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arkinrubbers.com"] [uri "/wp-login.php"] [unique_id "ajCyxcpsKyvb75pkSvaekwABwjo"], referer: https://arkinrubbers.com/wp-login.php
[Mon Jun 15 20:19:49.398487 2026] [security2:error] [pid 53359:tid 53611] [client 103.125.146.40:52935] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/theme-compat/config.php"] [unique_id "ajCyxfC2Xs1VMQlhsga-vAAAAog"]
[Mon Jun 15 20:19:49.639761 2026] [security2:error] [pid 51003:tid 51223] [client 57.141.14.73:57188] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "majividyarthikes.com"] [uri "/index.php"] [unique_id "ajCyxcpsKyvb75pkSvaelgAB6So"]
[Mon Jun 15 20:19:49.705237 2026] [security2:error] [pid 53359:tid 53504] [client 20.229.212.220:65011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.212.229.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "archresource.co"] [uri "/z.php"] [unique_id "ajCyxfC2Xs1VMQlhsga-xAAAAh0"]
[Mon Jun 15 20:19:49.777906 2026] [security2:error] [pid 53359:tid 53483] [remote 162.254.36.150:59890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.36.254.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mirrorbuzz.com"] [uri "/wp-login.php"] [unique_id "ajCyxfC2Xs1VMQlhsga-xgACHnU"], referer: https://mirrorbuzz.com/wp-login.php
[Mon Jun 15 20:19:49.845340 2026] [security2:error] [pid 51003:tid 51182] [client 103.125.146.69:43373] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/images/wp-config.php"] [unique_id "ajCyxcpsKyvb75pkSvaeoAAAAcA"]
[Mon Jun 15 20:19:49.880064 2026] [rewrite:error] [pid 51003:tid 51183] [client 47.79.197.208:43596] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:19:49.942439 2026] [security2:error] [pid 53359:tid 53578] [client 139.99.122.191:59578] ModSecurity: Access denied with code 406 (phase 1). Pattern match "xmlrpc\\\\.php" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "73"] [id "392331"] [rev "3"] [msg "Atomicorp.com WAF Rules: xmlrpc DOS attack"] [severity "CRITICAL"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCyxfC2Xs1VMQlhsga-yAAAAmc"]
[Mon Jun 15 20:19:49.942545 2026] [security2:error] [pid 53359:tid 53578] [client 139.99.122.191:59578] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCyxfC2Xs1VMQlhsga-yAAAAmc"]
[Mon Jun 15 20:19:49.975097 2026] [security2:error] [pid 53359:tid 53496] [client 82.102.18.190:52624] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.persnofinance.com"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ajCyxfC2Xs1VMQlhsga-ywAAAhU"]
[Mon Jun 15 20:19:49.992437 2026] [security2:error] [pid 53359:tid 53437] [remote 209.42.18.223:56878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.vertiport-holdings.us"] [uri "/wp-login.php"] [unique_id "ajCyxfC2Xs1VMQlhsga-zAACgkc"]
[Mon Jun 15 20:19:50.117059 2026] [security2:error] [pid 53359:tid 53527] [client 139.99.122.191:59598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.122.99.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srinivasgorthyandco.com"] [uri "/wp-login.php"] [unique_id "ajCyxvC2Xs1VMQlhsga-0gAAAjQ"]
[Mon Jun 15 20:19:50.252997 2026] [security2:error] [pid 51003:tid 51147] [client 103.125.146.68:43353] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/SimplePie/login.php"] [unique_id "ajCyxspsKyvb75pkSvaeqQAAAZ0"]
[Mon Jun 15 20:19:50.341602 2026] [rewrite:error] [pid 51003:tid 51220] [client 47.79.197.208:43596] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:19:50.465122 2026] [security2:error] [pid 51003:tid 51195] [client 20.229.212.220:65433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.212.229.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "archresource.co"] [uri "/bless.php"] [unique_id "ajCyxspsKyvb75pkSvaesQAAAc0"]
[Mon Jun 15 20:19:50.542626 2026] [security2:error] [pid 53359:tid 53523] [client 57.141.14.112:21162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyxvC2Xs1VMQlhsga-4QACMFk"]
[Mon Jun 15 20:19:50.632608 2026] [security2:error] [pid 51003:tid 51178] [client 103.125.146.57:44327] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/upgrade/config.php"] [unique_id "ajCyxspsKyvb75pkSvaeswAAAbw"]
[Mon Jun 15 20:19:50.658284 2026] [security2:error] [pid 53359:tid 53541] [client 112.86.225.47:53242] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.diggysguide.com"] [uri "/summer-trip-remastered/spanish-village"] [unique_id "ajCyxvC2Xs1VMQlhsga-6gAAAkI"]
[Mon Jun 15 20:19:50.658410 2026] [security2:error] [pid 53359:tid 53541] [client 112.86.225.47:53242] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.diggysguide.com"] [uri "/summer-trip-remastered/spanish-village"] [unique_id "ajCyxvC2Xs1VMQlhsga-6gAAAkI"]
[Mon Jun 15 20:19:50.763542 2026] [security2:error] [pid 51003:tid 51230] [client 139.99.122.191:59644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.122.99.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srinivasgorthyandco.com"] [uri "/wp-login.php"] [unique_id "ajCyxspsKyvb75pkSvaetQAAAfA"]
[Mon Jun 15 20:19:51.016724 2026] [security2:error] [pid 51003:tid 51171] [client 103.125.146.30:35111] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/SimplePie/wp-load.php"] [unique_id "ajCyx8psKyvb75pkSvaeuQAAAbU"]
[Mon Jun 15 20:19:51.168971 2026] [rewrite:error] [pid 53359:tid 53452] [remote 47.79.198.212:51452] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:19:51.366646 2026] [security2:error] [pid 53359:tid 53557] [client 20.229.212.220:49700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.212.229.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "archresource.co"] [uri "/hplfuns.php"] [unique_id "ajCyx_C2Xs1VMQlhsga--wAAAlI"]
[Mon Jun 15 20:19:51.423931 2026] [rewrite:error] [pid 53359:tid 53393] [remote 47.79.198.212:51452] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:19:51.429176 2026] [security2:error] [pid 53359:tid 53530] [client 103.125.146.36:64203] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/theme-compat/admin.php"] [unique_id "ajCyx_C2Xs1VMQlhsga-_QAAAjc"]
[Mon Jun 15 20:19:51.547361 2026] [security2:error] [pid 53359:tid 53543] [client 47.79.201.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "societytodaynews.com"] [uri "/index.php"] [unique_id "ajCyx_C2Xs1VMQlhsga--gAAAkQ"], referer: https://www.google.com/
[Mon Jun 15 20:19:51.563434 2026] [security2:error] [pid 53359:tid 53604] [client 66.249.79.192:60591] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anatma.org"] [uri "/index.php"] [unique_id "ajCyx_C2Xs1VMQlhsga-9AAAAoE"]
[Mon Jun 15 20:19:51.788983 2026] [security2:error] [pid 51003:tid 51088] [remote 57.141.14.14:43110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyx8psKyvb75pkSvaeygABlVQ"]
[Mon Jun 15 20:19:51.819000 2026] [security2:error] [pid 51003:tid 51253] [client 103.125.146.79:42511] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/images/media/config.php"] [unique_id "ajCyx8psKyvb75pkSvaezgAAAgc"]
[Mon Jun 15 20:19:52.125060 2026] [security2:error] [pid 53359:tid 53526] [client 45.166.207.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kthemani.com"] [uri "/index.php"] [unique_id "ajCyxvC2Xs1VMQlhsga-1wAAAjM"]
[Mon Jun 15 20:19:52.195569 2026] [security2:error] [pid 53359:tid 53528] [client 103.125.146.60:26253] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/languages/config.php"] [unique_id "ajCyyPC2Xs1VMQlhsga_EQAAAjU"]
[Mon Jun 15 20:19:52.235017 2026] [security2:error] [pid 53359:tid 53486] [remote 17.22.245.163:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.smgl.org"] [uri "/wp-content/uploads/2019/07/BBracelet202.jpg"] [unique_id "ajCyyPC2Xs1VMQlhsga_EwACR3g"]
[Mon Jun 15 20:19:52.343814 2026] [security2:error] [pid 51003:tid 51180] [client 20.229.212.220:50457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.212.229.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "archresource.co"] [uri "/lock.php"] [unique_id "ajCyyMpsKyvb75pkSvae4wAAAb4"]
[Mon Jun 15 20:19:52.436681 2026] [security2:error] [pid 53359:tid 53510] [client 57.141.14.47:22192] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "majividyarthikes.com"] [uri "/index.php"] [unique_id "ajCyyPC2Xs1VMQlhsga_EAACIw4"]
[Mon Jun 15 20:19:52.459582 2026] [security2:error] [pid 51003:tid 51140] [client 82.102.18.190:52638] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.persnofinance.com"] [uri "/autodiscover/autodiscover.xml/website/wp-includes/wlwmanifest.xml"] [unique_id "ajCyyMpsKyvb75pkSvae6AAAAZY"]
[Mon Jun 15 20:19:52.547280 2026] [security2:error] [pid 53359:tid 53491] [remote 185.109.19.192:40152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.19.109.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hydlab.co.in"] [uri "/wp-login.php"] [unique_id "ajCyyPC2Xs1VMQlhsga_GAACGH0"]
[Mon Jun 15 20:19:52.631753 2026] [security2:error] [pid 53359:tid 53617] [client 103.125.146.60:33653] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/fonts/config.php"] [unique_id "ajCyyPC2Xs1VMQlhsga_GwAAAo4"]
[Mon Jun 15 20:19:52.944033 2026] [rewrite:error] [pid 53359:tid 53610] [client 47.79.198.202:25144] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:19:53.031995 2026] [security2:error] [pid 51003:tid 51206] [client 20.229.212.220:50896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.212.229.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "archresource.co"] [uri "/radio.php"] [unique_id "ajCyycpsKyvb75pkSvae8QAAAdg"]
[Mon Jun 15 20:19:53.053587 2026] [security2:error] [pid 53359:tid 53589] [client 103.125.146.48:22063] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/upgrade/admin.php"] [unique_id "ajCyyfC2Xs1VMQlhsga_JgAAAnI"]
[Mon Jun 15 20:19:53.115051 2026] [security2:error] [pid 53359:tid 53396] [remote 185.109.19.192:40152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.19.109.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hydlab.co.in"] [uri "/wp-login.php"] [unique_id "ajCyyfC2Xs1VMQlhsga_KQACLB4"], referer: https://hydlab.co.in/wp-login.php
[Mon Jun 15 20:19:53.138967 2026] [security2:error] [pid 51003:tid 51239] [client 57.141.14.101:56902] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyycpsKyvb75pkSvae7wAB-RM"]
[Mon Jun 15 20:19:53.326877 2026] [rewrite:error] [pid 53359:tid 53473] [remote 47.79.198.255:56212] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:19:53.341092 2026] [security2:error] [pid 53359:tid 53534] [client 192.140.64.94:29848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.64.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCyyfC2Xs1VMQlhsga_MwAAAjs"]
[Mon Jun 15 20:19:53.341213 2026] [security2:error] [pid 53359:tid 53534] [client 192.140.64.94:29848] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCyyfC2Xs1VMQlhsga_MwAAAjs"]
[Mon Jun 15 20:19:53.425007 2026] [rewrite:error] [pid 53359:tid 53495] [client 47.79.198.202:25144] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:19:53.445299 2026] [security2:error] [pid 53359:tid 53591] [client 139.99.122.191:59772] ModSecurity: Access denied with code 406 (phase 1). Pattern match "xmlrpc\\\\.php" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "73"] [id "392331"] [rev "3"] [msg "Atomicorp.com WAF Rules: xmlrpc DOS attack"] [severity "CRITICAL"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCyyfC2Xs1VMQlhsga_OAAAAnQ"]
[Mon Jun 15 20:19:53.445417 2026] [security2:error] [pid 53359:tid 53591] [client 139.99.122.191:59772] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCyyfC2Xs1VMQlhsga_OAAAAnQ"]
[Mon Jun 15 20:19:53.482496 2026] [security2:error] [pid 51003:tid 51141] [client 103.125.146.41:43835] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/index/config.php"] [unique_id "ajCyycpsKyvb75pkSvafAAAAAZc"]
[Mon Jun 15 20:19:53.594475 2026] [rewrite:error] [pid 53359:tid 53485] [remote 47.79.198.255:56212] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:19:53.913929 2026] [security2:error] [pid 51003:tid 51200] [client 45.61.187.30:52812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.187.61.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.fountina.net"] [uri "/wp-login.php"] [unique_id "ajCyycpsKyvb75pkSvafDgAAAdI"]
[Mon Jun 15 20:19:53.918034 2026] [security2:error] [pid 53359:tid 53536] [client 103.125.146.63:62973] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/fonts/admin.php"] [unique_id "ajCyyfC2Xs1VMQlhsga_RwAAAj0"]
[Mon Jun 15 20:19:53.929060 2026] [security2:error] [pid 53359:tid 53467] [remote 74.7.227.173:47196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.rentswale.ehx.czu.mybluehostin.me"] [uri "/fonts/images/js/images/css/images/admin/uploads/img/subcategory.php"] [unique_id "ajCyyfC2Xs1VMQlhsga_SQACI2U"], referer: https://www.rentswale.ehx.czu.mybluehostin.me/fonts/images/js/images/css/images/admin/uploads/img/log.png
[Mon Jun 15 20:19:54.013477 2026] [security2:error] [pid 53359:tid 53585] [client 20.229.212.220:51566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.212.229.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "archresource.co"] [uri "/wp-content/themes/about.php"] [unique_id "ajCyyvC2Xs1VMQlhsga_TQAAAm4"]
[Mon Jun 15 20:19:54.226602 2026] [security2:error] [pid 53359:tid 53503] [client 139.99.122.191:59792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.122.99.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srinivasgorthyandco.com"] [uri "/wp-login.php"] [unique_id "ajCyyvC2Xs1VMQlhsga_UgAAAhw"]
[Mon Jun 15 20:19:54.276975 2026] [rewrite:error] [pid 51003:tid 51113] [remote 47.79.196.228:7434] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:19:54.280232 2026] [security2:error] [pid 51003:tid 51178] [client 82.102.18.190:36660] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.persnofinance.com"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "ajCyyspsKyvb75pkSvafGgAAAbw"]
[Mon Jun 15 20:19:54.303299 2026] [security2:error] [pid 51003:tid 51213] [client 57.141.14.33:53681] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fifthestate.agency"] [uri "/index.php"] [unique_id "ajCyycpsKyvb75pkSvafEQAB3wk"]
[Mon Jun 15 20:19:54.333373 2026] [security2:error] [pid 53359:tid 53560] [client 103.125.146.33:21375] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/images/crystal/"] [unique_id "ajCyyvC2Xs1VMQlhsga_VQAAAlU"]
[Mon Jun 15 20:19:54.532545 2026] [rewrite:error] [pid 51003:tid 51074] [remote 47.79.196.228:7434] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:19:54.579753 2026] [security2:error] [pid 51003:tid 51202] [client 217.181.91.223:18405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.91.181.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rajunandkardeputycollector.blog"] [uri "/wp-login.php"] [unique_id "ajCyyspsKyvb75pkSvafIgAAAdQ"], referer: https://rajunandkardeputycollector.blog/wp-login.php
[Mon Jun 15 20:19:54.655876 2026] [security2:error] [pid 53359:tid 53464] [remote 194.32.155.65:39108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.155.32.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "azrconsulting.in"] [uri "/wp-login.php"] [unique_id "ajCyyvC2Xs1VMQlhsga_WAACUGI"]
[Mon Jun 15 20:19:54.824204 2026] [security2:error] [pid 53359:tid 53403] [remote 194.32.155.65:39108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.155.32.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "azrconsulting.in"] [uri "/wp-login.php"] [unique_id "ajCyyvC2Xs1VMQlhsga_XwACWiU"], referer: https://azrconsulting.in/wp-login.php
[Mon Jun 15 20:19:54.831558 2026] [security2:error] [pid 53359:tid 53522] [client 103.125.146.73:36575] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/wp-load.php"] [unique_id "ajCyyvC2Xs1VMQlhsga_YAAAAi8"]
[Mon Jun 15 20:19:54.846256 2026] [security2:error] [pid 53359:tid 53575] [client 20.229.212.220:52260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.212.229.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "archresource.co"] [uri "/wp-content/upgrade/index.php"] [unique_id "ajCyyvC2Xs1VMQlhsga_YwAAAmQ"]
[Mon Jun 15 20:19:54.932067 2026] [security2:error] [pid 51003:tid 51167] [client 57.141.14.89:39046] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyyspsKyvb75pkSvafKQABsWI"]
[Mon Jun 15 20:19:55.228662 2026] [security2:error] [pid 53359:tid 53500] [client 103.163.220.5:34771] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/images/crystal/config.php"] [unique_id "ajCyy_C2Xs1VMQlhsga_eQAAAhk"]
[Mon Jun 15 20:19:55.252961 2026] [security2:error] [pid 51003:tid 51172] [client 57.141.14.74:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aarohiarts.org"] [uri "/index.php"] [unique_id "ajCyyspsKyvb75pkSvafMQAAAbY"]
[Mon Jun 15 20:19:55.436687 2026] [rewrite:error] [pid 53359:tid 53394] [remote 47.79.197.32:30844] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:19:55.606906 2026] [security2:error] [pid 51003:tid 51191] [client 20.229.212.220:52719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.212.229.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "archresource.co"] [uri "/wp-includes/fonts/index.php"] [unique_id "ajCyy8psKyvb75pkSvafQAAAAck"]
[Mon Jun 15 20:19:55.624196 2026] [security2:error] [pid 51003:tid 51143] [client 103.125.146.57:48823] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/languages/admin.php"] [unique_id "ajCyy8psKyvb75pkSvafQgAAAZk"]
[Mon Jun 15 20:19:55.648929 2026] [security2:error] [pid 51003:tid 51199] [client 82.102.18.190:39798] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.persnofinance.com"] [uri "/autodiscover/autodiscover.xml/news/wp-includes/wlwmanifest.xml"] [unique_id "ajCyy8psKyvb75pkSvafRQAAAdE"]
[Mon Jun 15 20:19:55.694725 2026] [rewrite:error] [pid 53359:tid 53382] [remote 47.79.197.32:30844] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:19:55.865631 2026] [security2:error] [pid 51003:tid 51243] [client 57.141.14.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kthemani.com"] [uri "/index.php"] [unique_id "ajCyycpsKyvb75pkSvafCgAAAf0"]
[Mon Jun 15 20:19:55.890882 2026] [security2:error] [pid 51003:tid 51212] [client 139.99.122.191:59850] ModSecurity: Access denied with code 406 (phase 1). Pattern match "xmlrpc\\\\.php" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "73"] [id "392331"] [rev "3"] [msg "Atomicorp.com WAF Rules: xmlrpc DOS attack"] [severity "CRITICAL"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCyy8psKyvb75pkSvafTAAAAd4"]
[Mon Jun 15 20:19:55.891005 2026] [security2:error] [pid 51003:tid 51212] [client 139.99.122.191:59850] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCyy8psKyvb75pkSvafTAAAAd4"]
[Mon Jun 15 20:19:55.954279 2026] [security2:error] [pid 51003:tid 51162] [client 81.173.162.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kthemani.com"] [uri "/index.php"] [unique_id "ajCyycpsKyvb75pkSvafDAABrB8"]
[Mon Jun 15 20:19:56.039765 2026] [security2:error] [pid 53359:tid 53593] [client 103.125.146.80:55797] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/js/dist/config.php"] [unique_id "ajCyzPC2Xs1VMQlhsga_igAAAnY"]
[Mon Jun 15 20:19:56.404563 2026] [rewrite:error] [pid 53359:tid 53492] [remote 47.79.198.139:42096] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:19:56.454643 2026] [security2:error] [pid 53359:tid 53554] [client 103.125.146.78:43423] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/settings.php"] [unique_id "ajCyzPC2Xs1VMQlhsga_ogAAAk8"]
[Mon Jun 15 20:19:56.497778 2026] [security2:error] [pid 53359:tid 53615] [client 20.229.212.220:53271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.212.229.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "archresource.co"] [uri "/ws.php"] [unique_id "ajCyzPC2Xs1VMQlhsga_pAAAAow"]
[Mon Jun 15 20:19:56.550317 2026] [security2:error] [pid 53359:tid 53513] [client 57.141.14.69:45284] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyzPC2Xs1VMQlhsga_oQACJl0"]
[Mon Jun 15 20:19:56.610923 2026] [security2:error] [pid 53359:tid 53535] [client 139.99.122.191:59864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.122.99.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srinivasgorthyandco.com"] [uri "/wp-login.php"] [unique_id "ajCyzPC2Xs1VMQlhsga_qAAAAjw"]
[Mon Jun 15 20:19:56.674069 2026] [rewrite:error] [pid 53359:tid 53373] [remote 47.79.198.139:42096] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:19:56.866228 2026] [security2:error] [pid 51003:tid 51224] [client 2a03:2880:f806:51:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ruchini.hemani.finance"] [uri "/index.php"] [unique_id "ajCyzMpsKyvb75pkSvafZgAB6hc"]
[Mon Jun 15 20:19:56.915462 2026] [security2:error] [pid 53359:tid 53532] [client 103.125.146.69:55265] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/SimplePie/Cache/Cache/config.php"] [unique_id "ajCyzPC2Xs1VMQlhsga_sgAAAjk"]
[Mon Jun 15 20:19:57.229671 2026] [security2:error] [pid 53359:tid 53550] [client 112.86.225.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ralphagro.com"] [uri "/index.php"] [unique_id "ajCyy_C2Xs1VMQlhsga_iQAAAks"]
[Mon Jun 15 20:19:57.331287 2026] [security2:error] [pid 53359:tid 53559] [client 103.125.146.43:48271] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/bootstrap.php"] [unique_id "ajCyzfC2Xs1VMQlhsga_tgAAAlQ"]
[Mon Jun 15 20:19:57.336060 2026] [security2:error] [pid 53359:tid 53582] [client 20.229.212.220:53890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.212.229.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "archresource.co"] [uri "/ws49.php"] [unique_id "ajCyzfC2Xs1VMQlhsga_twAAAms"]
[Mon Jun 15 20:19:57.549052 2026] [security2:error] [pid 53359:tid 53614] [client 2a09:bac5:55fe:25d7::3c5:1c:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "travelmax.in"] [uri "/wp-login.php/wp-login.php"] [unique_id "ajCyzfC2Xs1VMQlhsga_vQAAAos"]
[Mon Jun 15 20:19:57.738873 2026] [security2:error] [pid 51003:tid 51182] [client 103.125.146.42:55795] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/ad0ceddb/config.php"] [unique_id "ajCyzcpsKyvb75pkSvafdgAAAcA"]
[Mon Jun 15 20:19:58.038802 2026] [security2:error] [pid 51003:tid 51254] [client 82.102.18.190:39802] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.persnofinance.com"] [uri "/autodiscover/autodiscover.xml/2018/wp-includes/wlwmanifest.xml"] [unique_id "ajCyzspsKyvb75pkSvaffQAAAgg"]
[Mon Jun 15 20:19:58.149178 2026] [security2:error] [pid 53359:tid 53586] [client 103.125.146.42:62027] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/js/wp-load.php"] [unique_id "ajCyzvC2Xs1VMQlhsga_0gAAAm8"]
[Mon Jun 15 20:19:58.159851 2026] [security2:error] [pid 51003:tid 51205] [client 57.141.14.73:37954] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyzspsKyvb75pkSvaffgAB1xY"]
[Mon Jun 15 20:19:58.189683 2026] [security2:error] [pid 51003:tid 51062] [remote 103.127.30.137:50022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.30.127.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brandkare.com"] [uri "/wp-login.php"] [unique_id "ajCyzspsKyvb75pkSvafgwACCjo"]
[Mon Jun 15 20:19:58.270338 2026] [security2:error] [pid 51003:tid 51234] [client 20.229.212.220:54524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.212.229.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "archresource.co"] [uri "/xmlrpc.php"] [unique_id "ajCyzspsKyvb75pkSvafiAAAAfQ"]
[Mon Jun 15 20:19:58.573166 2026] [rewrite:error] [pid 53359:tid 53433] [remote 47.79.197.210:13822] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:19:58.583741 2026] [security2:error] [pid 53359:tid 53563] [client 139.99.122.191:59908] ModSecurity: Access denied with code 406 (phase 1). Pattern match "xmlrpc\\\\.php" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "73"] [id "392331"] [rev "3"] [msg "Atomicorp.com WAF Rules: xmlrpc DOS attack"] [severity "CRITICAL"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCyzvC2Xs1VMQlhsga_2gAAAlg"]
[Mon Jun 15 20:19:58.583849 2026] [security2:error] [pid 53359:tid 53563] [client 139.99.122.191:59908] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "srinivasgorthyandco.com"] [uri "/xmlrpc.php"] [unique_id "ajCyzvC2Xs1VMQlhsga_2gAAAlg"]
[Mon Jun 15 20:19:58.616168 2026] [security2:error] [pid 51003:tid 51185] [client 103.125.146.59:41041] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/footer.php"] [unique_id "ajCyzspsKyvb75pkSvafjwAAAcM"]
[Mon Jun 15 20:19:58.674965 2026] [security2:error] [pid 51003:tid 51046] [remote 103.127.30.137:50022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.30.127.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brandkare.com"] [uri "/wp-login.php"] [unique_id "ajCyzspsKyvb75pkSvafkAABpCo"], referer: https://brandkare.com/wp-login.php
[Mon Jun 15 20:19:58.839134 2026] [rewrite:error] [pid 53359:tid 53450] [remote 47.79.197.210:13822] AH10411: Rewritten query string contains control characters or spaces
[Mon Jun 15 20:19:58.918170 2026] [security2:error] [pid 53359:tid 53569] [client 57.141.14.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "chicceleb.com"] [uri "/index.php"] [unique_id "ajCyzvC2Xs1VMQlhsga_2wAAAl4"]
[Mon Jun 15 20:19:59.022491 2026] [security2:error] [pid 53359:tid 53601] [client 103.125.146.33:32851] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/SimplePie/Cache/config.php"] [unique_id "ajCyz_C2Xs1VMQlhsga_6gAAAn4"]
[Mon Jun 15 20:19:59.131219 2026] [security2:error] [pid 53359:tid 53615] [client 82.102.18.190:39808] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.persnofinance.com"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "ajCyz_C2Xs1VMQlhsga_8AAAAow"]
[Mon Jun 15 20:19:59.329240 2026] [security2:error] [pid 53359:tid 53599] [client 2a09:bac5:55fb:25d7::3c5:1c:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "travelmax.in"] [uri "/wp-login.php"] [unique_id "ajCyz_C2Xs1VMQlhsga__AAAAnw"], referer: http://travelmax.in/wp-login.php
[Mon Jun 15 20:19:59.351423 2026] [security2:error] [pid 51003:tid 51239] [client 139.99.122.191:59924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.122.99.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srinivasgorthyandco.com"] [uri "/wp-login.php"] [unique_id "ajCyz8psKyvb75pkSvafoAAAAfk"]
[Mon Jun 15 20:19:59.387073 2026] [security2:error] [pid 51003:tid 51224] [client 103.125.146.76:39953] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/js/settings.php"] [unique_id "ajCyz8psKyvb75pkSvafoQAAAeo"]
[Mon Jun 15 20:19:59.462559 2026] [security2:error] [pid 53359:tid 53611] [client 57.141.14.44:44261] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCyz_C2Xs1VMQlhsga__QACiDE"]
[Mon Jun 15 20:19:59.465685 2026] [security2:error] [pid 53359:tid 53551] [client 20.229.212.220:55089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.212.229.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "archresource.co"] [uri "/xozx.php"] [unique_id "ajCyz_C2Xs1VMQlhsga__wAAAkw"]
[Mon Jun 15 20:19:59.583037 2026] [security2:error] [pid 53359:tid 53589] [client 79.90.222.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kthemani.com"] [uri "/index.php"] [unique_id "ajCyzfC2Xs1VMQlhsga_ygAAAnI"]
[Mon Jun 15 20:19:59.786516 2026] [security2:error] [pid 51003:tid 51165] [client 103.125.146.39:23841] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/core.php"] [unique_id "ajCyz8psKyvb75pkSvafpwAAAa8"]
[Mon Jun 15 20:19:59.799272 2026] [security2:error] [pid 53359:tid 53613] [client 31.219.209.201:57289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.209.219.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCyz_C2Xs1VMQlhsgbACQAAAoo"]
[Mon Jun 15 20:19:59.799407 2026] [security2:error] [pid 53359:tid 53613] [client 31.219.209.201:57289] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healingessence.in"] [uri "/xmlrpc.php"] [unique_id "ajCyz_C2Xs1VMQlhsgbACQAAAoo"]
[Mon Jun 15 20:20:00.050725 2026] [security2:error] [pid 53359:tid 53557] [client 82.102.18.190:63839] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.persnofinance.com"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "ajCy0PC2Xs1VMQlhsgbADwAAAlI"]
[Mon Jun 15 20:20:00.124846 2026] [security2:error] [pid 51003:tid 51184] [client 159.89.5.19:55702] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "spandanmumbai.org"] [uri "/wp-login.php"] [unique_id "ajCy0MpsKyvb75pkSvafsgAAAcI"]
[Mon Jun 15 20:20:00.167413 2026] [security2:error] [pid 53359:tid 53569] [client 2a09:bac5:55fb:25d7::3c5:1c:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "travelmax.in"] [uri "/wp-login.php"] [unique_id "ajCy0PC2Xs1VMQlhsgbAEgAAAl4"], referer: http://travelmax.in/wp-login.php
[Mon Jun 15 20:20:00.184357 2026] [security2:error] [pid 51003:tid 51176] [client 20.229.212.220:55817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.212.229.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "archresource.co"] [uri "/xwx1.php"] [unique_id "ajCy0MpsKyvb75pkSvafuwAAAbo"]
[Mon Jun 15 20:20:00.192426 2026] [security2:error] [pid 51003:tid 51138] [client 103.125.146.42:57607] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/images/smilies/config.php"] [unique_id "ajCy0MpsKyvb75pkSvafvQAAAZQ"]
[Mon Jun 15 20:20:00.593998 2026] [security2:error] [pid 53359:tid 53499] [client 40.77.167.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.jalanbuilders.com"] [uri "/index.php"] [unique_id "ajCyzvC2Xs1VMQlhsga_5AAAAhg"]
[Mon Jun 15 20:20:00.618636 2026] [security2:error] [pid 51003:tid 51227] [client 103.125.146.64:56121] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-admin/user/config.php"] [unique_id "ajCy0MpsKyvb75pkSvafxwAAAe0"]
[Mon Jun 15 20:20:00.649266 2026] [security2:error] [pid 53359:tid 53412] [remote 93.125.18.219:33876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.18.125.93.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radiantacademyandplacement.com"] [uri "/wp-login.php"] [unique_id "ajCy0PC2Xs1VMQlhsgbAFwACeC4"]
[Mon Jun 15 20:20:01.007144 2026] [security2:error] [pid 53359:tid 53555] [client 103.125.146.34:45749] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/SimplePie/config.php"] [unique_id "ajCy0fC2Xs1VMQlhsgbAJgAAAlA"]
[Mon Jun 15 20:20:01.008722 2026] [security2:error] [pid 53359:tid 53456] [remote 93.125.18.219:33876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.18.125.93.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "radiantacademyandplacement.com"] [uri "/wp-login.php"] [unique_id "ajCy0fC2Xs1VMQlhsgbAJwACLFo"], referer: https://radiantacademyandplacement.com/wp-login.php
[Mon Jun 15 20:20:01.322135 2026] [security2:error] [pid 53359:tid 53620] [client 20.229.212.220:56352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.212.229.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "archresource.co"] [uri "/Cap.php"] [unique_id "ajCy0fC2Xs1VMQlhsgbALQAAApE"]
[Mon Jun 15 20:20:01.398489 2026] [security2:error] [pid 53359:tid 53505] [client 103.125.146.63:25525] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/js/config.php"] [unique_id "ajCy0fC2Xs1VMQlhsgbANgAAAh4"]
[Mon Jun 15 20:20:01.577434 2026] [security2:error] [pid 53359:tid 53618] [client 82.102.18.190:39824] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.persnofinance.com"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ajCy0fC2Xs1VMQlhsgbAOgAAAo8"]
[Mon Jun 15 20:20:01.698301 2026] [security2:error] [pid 53359:tid 53563] [client 57.141.14.111:60812] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCy0fC2Xs1VMQlhsgbAOQACWH0"]
[Mon Jun 15 20:20:01.718240 2026] [security2:error] [pid 53359:tid 53535] [client 45.162.201.102:46642] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nctindia.org"] [uri "/index.php"] [unique_id "ajCy0PC2Xs1VMQlhsgbAEAAAAjw"]
[Mon Jun 15 20:20:01.815757 2026] [security2:error] [pid 51003:tid 51174] [client 103.125.146.38:64009] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/wp-config.php"] [unique_id "ajCy0cpsKyvb75pkSvaf3wAAAbg"]
[Mon Jun 15 20:20:02.249058 2026] [security2:error] [pid 53359:tid 53550] [client 103.125.146.38:57625] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/js/imgareaselect/config.php"] [unique_id "ajCy0vC2Xs1VMQlhsgbATQAAAks"]
[Mon Jun 15 20:20:02.322224 2026] [security2:error] [pid 53359:tid 53617] [client 20.229.212.220:57053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.212.229.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "archresource.co"] [uri "/ahax.php"] [unique_id "ajCy0vC2Xs1VMQlhsgbATwAAAo4"]
[Mon Jun 15 20:20:02.462063 2026] [security2:error] [pid 53359:tid 53499] [client 57.141.14.26:48282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCy0vC2Xs1VMQlhsgbAUQACGAo"]
[Mon Jun 15 20:20:02.513411 2026] [security2:error] [pid 53359:tid 53407] [remote 3.216.227.216:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.abhijeetshirke.in"] [uri "/mauritius-future-sustainable-energy/"] [unique_id "ajCy0vC2Xs1VMQlhsgbAYwACeik"]
[Mon Jun 15 20:20:02.693533 2026] [security2:error] [pid 53359:tid 53519] [client 103.125.146.57:24211] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-admin/images/config.php"] [unique_id "ajCy0vC2Xs1VMQlhsgbAawAAAiw"]
[Mon Jun 15 20:20:02.913607 2026] [security2:error] [pid 51003:tid 51242] [client 49.37.157.202:61406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "desidelightmp.com"] [uri "/xmlrpc.php"] [unique_id "ajCy0spsKyvb75pkSvaf9AAAAfw"]
[Mon Jun 15 20:20:02.913790 2026] [security2:error] [pid 51003:tid 51242] [client 49.37.157.202:61406] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "desidelightmp.com"] [uri "/xmlrpc.php"] [unique_id "ajCy0spsKyvb75pkSvaf9AAAAfw"]
[Mon Jun 15 20:20:03.085578 2026] [security2:error] [pid 53359:tid 53613] [client 103.125.146.70:44859] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/includes.php"] [unique_id "ajCy0_C2Xs1VMQlhsgbAfwAAAoo"]
[Mon Jun 15 20:20:03.132652 2026] [security2:error] [pid 53359:tid 53582] [client 247.33.254.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCy0vC2Xs1VMQlhsgbAZwACa0k"], referer: https://mywordsnthoughts.com/malargal-kaettaen-song-from-ok-kanmani-tamil-lyrics-in-english-with-translation/
[Mon Jun 15 20:20:03.214498 2026] [security2:error] [pid 53359:tid 53472] [remote 247.33.254.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCy0vC2Xs1VMQlhsgbAbAACZmo"], referer: https://mywordsnthoughts.com/malargal-kaettaen-song-from-ok-kanmani-tamil-lyrics-in-english-with-translation/
[Mon Jun 15 20:20:03.515206 2026] [security2:error] [pid 51003:tid 51183] [client 103.125.146.64:45089] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-admin/wp-load.php"] [unique_id "ajCy08psKyvb75pkSvaf_gAAAcE"]
[Mon Jun 15 20:20:03.539490 2026] [security2:error] [pid 53359:tid 53562] [client 57.141.14.83:42804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fifthestate.agency"] [uri "/index.php"] [unique_id "ajCy0_C2Xs1VMQlhsgbAhQACVws"]
[Mon Jun 15 20:20:03.774809 2026] [security2:error] [pid 53359:tid 53525] [client 57.141.14.21:59971] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCy0_C2Xs1VMQlhsgbAkQACMhY"]
[Mon Jun 15 20:20:03.838610 2026] [security2:error] [pid 53359:tid 53580] [client 192.140.64.94:29624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.64.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCy0_C2Xs1VMQlhsgbAlgAAAmk"]
[Mon Jun 15 20:20:03.841420 2026] [security2:error] [pid 53359:tid 53580] [client 192.140.64.94:29624] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pepperic.com"] [uri "/xmlrpc.php"] [unique_id "ajCy0_C2Xs1VMQlhsgbAlgAAAmk"]
[Mon Jun 15 20:20:03.941118 2026] [security2:error] [pid 51003:tid 51239] [client 103.125.146.76:21237] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/uploads/settings.php"] [unique_id "ajCy08psKyvb75pkSvagCwAAAfk"]
[Mon Jun 15 20:20:04.118572 2026] [security2:error] [pid 53359:tid 53514] [client 20.229.212.220:57701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.212.229.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "archresource.co"] [uri "/byrgo.php"] [unique_id "ajCy1PC2Xs1VMQlhsgbAlwAAAic"]
[Mon Jun 15 20:20:04.155117 2026] [security2:error] [pid 51003:tid 51182] [client 82.102.18.190:47946] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.persnofinance.com"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "ajCy1MpsKyvb75pkSvagDgAAAcA"]
[Mon Jun 15 20:20:04.321201 2026] [security2:error] [pid 51003:tid 51214] [client 104.207.53.124:23931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.53.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rajunandkardeputycollector.blog"] [uri "/wp-login.php"] [unique_id "ajCy1MpsKyvb75pkSvagEwAAAeA"], referer: https://rajunandkardeputycollector.blog/wp-login.php
[Mon Jun 15 20:20:04.427679 2026] [security2:error] [pid 53359:tid 53551] [client 103.125.146.54:37811] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/SimplePie/Parse/config.php"] [unique_id "ajCy1PC2Xs1VMQlhsgbAngAAAkw"]
[Mon Jun 15 20:20:04.841254 2026] [security2:error] [pid 51003:tid 51148] [client 103.125.146.38:40369] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/rest-api/search/config.php"] [unique_id "ajCy1MpsKyvb75pkSvagKAAAAZ4"]
[Mon Jun 15 20:20:04.884683 2026] [security2:error] [pid 51003:tid 51072] [remote 103.127.30.137:50030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.30.127.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hydurbanrealty.com"] [uri "/wp-login.php"] [unique_id "ajCy1MpsKyvb75pkSvagKQABxEQ"]
[Mon Jun 15 20:20:04.916415 2026] [security2:error] [pid 51003:tid 51225] [client 45.197.196.15:60886] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "wantpg.com"] [uri "/public/index.php/pg-in-olude-araromi-1737252"] [unique_id "ajCy1MpsKyvb75pkSvagKgAAAes"]
[Mon Jun 15 20:20:04.931418 2026] [security2:error] [pid 51003:tid 51158] [client 20.229.212.220:58420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.212.229.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "archresource.co"] [uri "/css/index.php"] [unique_id "ajCy1MpsKyvb75pkSvagKwAAAag"]
[Mon Jun 15 20:20:04.968027 2026] [security2:error] [pid 51003:tid 51038] [remote 160.119.64.32:48682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.64.119.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healtyhemp.com"] [uri "/wp-login.php"] [unique_id "ajCy1MpsKyvb75pkSvagLQAB_SI"]
[Mon Jun 15 20:20:05.110945 2026] [security2:error] [pid 53359:tid 53515] [client 40.77.167.243:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "leapinfosys.com"] [uri "/index.php"] [unique_id "ajCy0vC2Xs1VMQlhsgbAZgACKFs"], referer: https://leapinfosys.com/benefits-of-lighting-management-system/
[Mon Jun 15 20:20:05.143739 2026] [security2:error] [pid 51003:tid 51045] [remote 160.119.64.32:48682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.64.119.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healtyhemp.com"] [uri "/wp-login.php"] [unique_id "ajCy1cpsKyvb75pkSvagMwAB1yk"], referer: https://healtyhemp.com/wp-login.php
[Mon Jun 15 20:20:05.232889 2026] [security2:error] [pid 53359:tid 53524] [client 103.125.146.72:45389] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/js/login.php"] [unique_id "ajCy1fC2Xs1VMQlhsgbAtQAAAjE"]
[Mon Jun 15 20:20:05.259633 2026] [security2:error] [pid 51003:tid 51226] [client 82.102.18.190:47952] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.persnofinance.com"] [uri "/autodiscover/autodiscover.xml/media/wp-includes/wlwmanifest.xml"] [unique_id "ajCy1cpsKyvb75pkSvagNQAAAew"]
[Mon Jun 15 20:20:05.360001 2026] [security2:error] [pid 51003:tid 51021] [remote 103.127.30.137:50030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.30.127.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hydurbanrealty.com"] [uri "/wp-login.php"] [unique_id "ajCy1cpsKyvb75pkSvagOQAB6BE"], referer: https://hydurbanrealty.com/wp-login.php
[Mon Jun 15 20:20:05.617412 2026] [security2:error] [pid 53359:tid 53510] [client 103.125.146.78:24849] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/main.php"] [unique_id "ajCy1fC2Xs1VMQlhsgbAvAAAAiM"]
[Mon Jun 15 20:20:05.647401 2026] [security2:error] [pid 51003:tid 51181] [client 20.229.212.220:58989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.212.229.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "archresource.co"] [uri "/jp.php"] [unique_id "ajCy1cpsKyvb75pkSvagTAAAAb8"]
[Mon Jun 15 20:20:05.992061 2026] [security2:error] [pid 51003:tid 51027] [remote 57.141.14.67:44235] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCy1cpsKyvb75pkSvagUgAB9Bc"]
[Mon Jun 15 20:20:05.996723 2026] [security2:error] [pid 53359:tid 53421] [remote 3.222.85.38:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.abhijeetshirke.in"] [uri "/cactus-plantation-for-a-sustainable-future/"] [unique_id "ajCy1fC2Xs1VMQlhsgbAyAACGzc"]
[Mon Jun 15 20:20:06.026317 2026] [security2:error] [pid 53359:tid 53522] [client 103.125.146.32:54261] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/backup-migration/backups/config.php"] [unique_id "ajCy1vC2Xs1VMQlhsgbAygAAAi8"]
[Mon Jun 15 20:20:06.334704 2026] [security2:error] [pid 51003:tid 51210] [client 36.65.188.235:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kthemani.com"] [uri "/index.php"] [unique_id "ajCy1MpsKyvb75pkSvagFgAB3GI"]
[Mon Jun 15 20:20:06.414314 2026] [security2:error] [pid 51003:tid 51098] [remote 192.169.174.130:21222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.174.169.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "smartgen.co.in"] [uri "/wp-login.php"] [unique_id "ajCy1spsKyvb75pkSvagbQABk14"]
[Mon Jun 15 20:20:06.422917 2026] [security2:error] [pid 53359:tid 53539] [client 103.125.146.60:45027] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/SimplePie/XML/config.php"] [unique_id "ajCy1vC2Xs1VMQlhsgbA2wAAAkA"]
[Mon Jun 15 20:20:06.492626 2026] [security2:error] [pid 53359:tid 53595] [client 20.229.212.220:59429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.212.229.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "archresource.co"] [uri "/num.php"] [unique_id "ajCy1vC2Xs1VMQlhsgbA4wAAAng"]
[Mon Jun 15 20:20:06.525967 2026] [security2:error] [pid 51003:tid 51186] [client 87.250.224.224:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "pranshuarora.com"] [uri "/index.php"] [unique_id "ajCy1spsKyvb75pkSvagWwAAAcQ"], referer: https://pranshuarora.com/
[Mon Jun 15 20:20:06.772464 2026] [security2:error] [pid 51003:tid 51217] [client 82.102.18.190:36475] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.persnofinance.com"] [uri "/autodiscover/autodiscover.xml/wp2/wp-includes/wlwmanifest.xml"] [unique_id "ajCy1spsKyvb75pkSvagcgAAAeM"]
[Mon Jun 15 20:20:06.810927 2026] [security2:error] [pid 53359:tid 53504] [client 103.125.146.38:29065] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/rest-api/endpoints/config.php"] [unique_id "ajCy1vC2Xs1VMQlhsgbA6QAAAh0"]
[Mon Jun 15 20:20:07.012221 2026] [security2:error] [pid 53359:tid 53433] [remote 91.146.99.41:55668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.99.146.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "leafpuffs.com"] [uri "/wp-login.php"] [unique_id "ajCy1vC2Xs1VMQlhsgbA7gACMUM"]
[Mon Jun 15 20:20:07.068511 2026] [security2:error] [pid 53359:tid 53571] [client 20.229.212.220:60029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.212.229.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "archresource.co"] [uri "/wp-content/themes/index.php"] [unique_id "ajCy1_C2Xs1VMQlhsgbA7wAAAmA"]
[Mon Jun 15 20:20:07.239716 2026] [security2:error] [pid 53359:tid 53406] [remote 91.146.99.41:55668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.99.146.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "leafpuffs.com"] [uri "/wp-login.php"] [unique_id "ajCy1_C2Xs1VMQlhsgbA-gACdSg"], referer: https://leafpuffs.com/wp-login.php
[Mon Jun 15 20:20:07.247330 2026] [security2:error] [pid 53359:tid 53549] [client 57.141.14.63:26278] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCy1_C2Xs1VMQlhsgbA9AACSnQ"]
[Mon Jun 15 20:20:07.280015 2026] [security2:error] [pid 53359:tid 53408] [remote 111.225.149.140:27268] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.puzzleadventureguide.com"] [uri "/en/the-prophecy/love-nest"] [unique_id "ajCy1_C2Xs1VMQlhsgbA-wACKSo"]
[Mon Jun 15 20:20:07.514877 2026] [security2:error] [pid 53359:tid 53564] [client 103.125.146.67:61297] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/backup-migration/login.php"] [unique_id "ajCy1_C2Xs1VMQlhsgbA_gAAAlk"]
[Mon Jun 15 20:20:07.797237 2026] [security2:error] [pid 53359:tid 53503] [client 20.229.212.220:60381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.212.229.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "archresource.co"] [uri "/12.php"] [unique_id "ajCy1_C2Xs1VMQlhsgbBDAAAAhw"]
[Mon Jun 15 20:20:07.927717 2026] [security2:error] [pid 53359:tid 53555] [client 103.125.146.53:54155] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/rest-api/login.php"] [unique_id "ajCy1_C2Xs1VMQlhsgbBEAAAAlA"]
[Mon Jun 15 20:20:08.042143 2026] [security2:error] [pid 53359:tid 53562] [client 82.102.18.190:47970] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.persnofinance.com"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "ajCy2PC2Xs1VMQlhsgbBFwAAAlc"]
[Mon Jun 15 20:20:08.269858 2026] [fcgid:warn] [pid 53359:tid 53554] (70014)End of file found: [client 157.245.201.21:60530] mod_fcgid: can't get data from http client
[Mon Jun 15 20:20:08.313330 2026] [security2:error] [pid 53359:tid 53534] [client 103.163.220.5:40109] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "ajCy2PC2Xs1VMQlhsgbBHgAAAjs"]
[Mon Jun 15 20:20:08.546611 2026] [fcgid:warn] [pid 51003:tid 51142] (70014)End of file found: [client 157.245.201.21:60567] mod_fcgid: can't get data from http client
[Mon Jun 15 20:20:08.641509 2026] [security2:error] [pid 53359:tid 53558] [client 20.229.212.220:61081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.212.229.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "archresource.co"] [uri "/Ov-Simple1.php"] [unique_id "ajCy2PC2Xs1VMQlhsgbBMgAAAlM"]
[Mon Jun 15 20:20:08.719651 2026] [security2:error] [pid 53359:tid 53390] [remote 157.55.39.58:1864] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ybsolutions.in"] [uri "/index.php"] [unique_id "ajCy2PC2Xs1VMQlhsgbBNAACeBg"]
[Mon Jun 15 20:20:08.739920 2026] [security2:error] [pid 53359:tid 53526] [client 57.141.14.78:49142] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCy2PC2Xs1VMQlhsgbBMAACM1k"]
[Mon Jun 15 20:20:08.747397 2026] [security2:error] [pid 53359:tid 53517] [client 220.181.108.114:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "binnyseasyrecipes.com"] [uri "/index.php"] [unique_id "ajCy2PC2Xs1VMQlhsgbBLgAAAio"]
[Mon Jun 15 20:20:08.748606 2026] [security2:error] [pid 51003:tid 51166] [client 213.180.203.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCy2MpsKyvb75pkSvagkQAAAbA"]
[Mon Jun 15 20:20:08.750848 2026] [security2:error] [pid 53359:tid 53499] [client 213.180.203.118:33566] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCy2PC2Xs1VMQlhsgbBMwACGCY"]
[Mon Jun 15 20:20:08.816964 2026] [security2:error] [pid 53359:tid 53555] [client 103.125.146.70:39763] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/uploads/wc-logs/config.php"] [unique_id "ajCy2PC2Xs1VMQlhsgbBQQAAAlA"]
[Mon Jun 15 20:20:08.847261 2026] [security2:error] [pid 53359:tid 53515] [client 157.55.39.58:1864] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ybsolutions.in"] [uri "/index.php"] [unique_id "ajCy2PC2Xs1VMQlhsgbBQAACKGA"]
[Mon Jun 15 20:20:08.918956 2026] [security2:error] [pid 53359:tid 53574] [client 157.55.39.58:1864] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ybsolutions.in"] [uri "/index.php"] [unique_id "ajCy2PC2Xs1VMQlhsgbBQgACYy4"]
[Mon Jun 15 20:20:08.930505 2026] [security2:error] [pid 51003:tid 51053] [remote 104.155.29.73:55085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.29.155.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intellectfaidei.com"] [uri "/wp-login.php"] [unique_id "ajCy2MpsKyvb75pkSvagmQABtDE"]
[Mon Jun 15 20:20:09.111375 2026] [security2:error] [pid 51003:tid 51129] [remote 104.155.29.73:55085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.29.155.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intellectfaidei.com"] [uri "/wp-login.php"] [unique_id "ajCy2cpsKyvb75pkSvagnQABon0"], referer: https://intellectfaidei.com/wp-login.php
[Mon Jun 15 20:20:09.131995 2026] [security2:error] [pid 53359:tid 53369] [remote 74.7.227.161:58924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.shreeramsweets.co.in"] [uri "/plugins/lightgallery/js/plugins/lightgallery/js/images_scroller/images/blog/grid/images_scroller/plugins/owl-carousel/css/images/images_scroller/catering.php"] [unique_id "ajCy2fC2Xs1VMQlhsgbBSgACdgM"], referer: https://www.shreeramsweets.co.in/plugins/lightgallery/js/plugins/lightgallery/js/images_scroller/images/blog/grid/images_scroller/plugins/owl-carousel/css/images/images_scroller/banner2.jpg
[Mon Jun 15 20:20:09.142757 2026] [security2:error] [pid 53359:tid 53506] [client 82.102.18.190:47982] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.persnofinance.com"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "ajCy2fC2Xs1VMQlhsgbBSwAAAh8"]
[Mon Jun 15 20:20:09.185232 2026] [security2:error] [pid 51003:tid 51147] [client 57.141.14.95:24611] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "majividyarthikes.com"] [uri "/index.php"] [unique_id "ajCy2MpsKyvb75pkSvagmgABnRk"]
[Mon Jun 15 20:20:09.282202 2026] [security2:error] [pid 53359:tid 53600] [client 47.79.206.189:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "societytodaynews.com"] [uri "/index.php"] [unique_id "ajCy2PC2Xs1VMQlhsgbBRwAAAn0"], referer: https://www.google.com/
[Mon Jun 15 20:20:09.347202 2026] [security2:error] [pid 51003:tid 51180] [client 193.189.100.196:65183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.100.189.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jalanbuilders.com"] [uri "/altitude/xmlrpc.php"] [unique_id "ajCy2cpsKyvb75pkSvagpQAAAb4"]
[Mon Jun 15 20:20:09.481294 2026] [security2:error] [pid 51003:tid 51180] [client 193.189.100.196:65183] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jalanbuilders.com"] [uri "/altitude/xmlrpc.php"] [unique_id "ajCy2cpsKyvb75pkSvagpQAAAb4"]
[Mon Jun 15 20:20:09.485182 2026] [security2:error] [pid 53359:tid 53557] [client 20.229.212.220:61607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.212.229.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "archresource.co"] [uri "/an.php"] [unique_id "ajCy2fC2Xs1VMQlhsgbBVAAAAlI"]
[Mon Jun 15 20:20:09.742177 2026] [security2:error] [pid 51003:tid 51217] [client 91.92.178.195:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mywordsnthoughts.com"] [uri "/index.php"] [unique_id "ajCy2cpsKyvb75pkSvagrQAB43k"]
[Mon Jun 15 20:20:09.895233 2026] [security2:error] [pid 51003:tid 51068] [remote 2a03:2880:f806:9:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ruchini.hemani.finance"] [uri "/index.php"] [unique_id "ajCy2cpsKyvb75pkSvagswACBEA"]
[Mon Jun 15 20:20:09.947306 2026] [security2:error] [pid 53359:tid 53566] [client 64.176.38.237:59403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.38.176.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelgrandpalacecbe.com"] [uri "/inputs.php"] [unique_id "ajCy2fC2Xs1VMQlhsgbBZQAAAls"]
[Mon Jun 15 20:20:09.990602 2026] [security2:error] [pid 51003:tid 51236] [client 57.141.14.109:57830] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rohandasgupta.com"] [uri "/index.php"] [unique_id "ajCy2cpsKyvb75pkSvagqAAB9gI"]
[Mon Jun 15 20:20:10.048088 2026] [security2:error] [pid 53359:tid 53614] [client 57.141.14.86:25086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koyeldasguptanaha.com"] [uri "/index.php"] [unique_id "ajCy2fC2Xs1VMQlhsgbBYwACiwI"]
[Mon Jun 15 20:20:10.070523 2026] [security2:error] [pid 53359:tid 53537] [client 57.141.14.73:53202] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "wantpg.com"] [uri "/public/index.php/in/karisho-hokkaido-japan-1298827.html"] [unique_id "ajCy2vC2Xs1VMQlhsgbBagACPlM"]
[Mon Jun 15 20:20:10.142157 2026] [security2:error] [pid 53359:tid 53580] [client 95.108.213.97:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCy2vC2Xs1VMQlhsgbBbAAAAmk"]
[Mon Jun 15 20:20:10.192761 2026] [security2:error] [pid 53359:tid 53508] [client 95.108.213.97:65026] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "demo.nxtal.com"] [uri "/ps/adminps/index.php/security/compromised"] [unique_id "ajCy2fC2Xs1VMQlhsgbBYAACIVo"]
[Mon Jun 15 20:20:10.214144 2026] [security2:error] [pid 53359:tid 53536] [client 103.125.146.59:39159] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-content/backup-migration/config.php"] [unique_id "ajCy2vC2Xs1VMQlhsgbBbgAAAj0"]
[Mon Jun 15 20:20:10.337705 2026] [security2:error] [pid 51003:tid 51159] [client 116.179.32.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "binnyseasyrecipes.com"] [uri "/index.php"] [unique_id "ajCy2spsKyvb75pkSvaguQAAAak"]
[Mon Jun 15 20:20:10.357452 2026] [security2:error] [pid 51003:tid 51138] [client 64.176.38.237:60029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.38.176.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelgrandpalacecbe.com"] [uri "/admin.php"] [unique_id "ajCy2spsKyvb75pkSvagwAAAAZQ"]
[Mon Jun 15 20:20:10.458707 2026] [security2:error] [pid 51003:tid 51257] [client 20.229.212.220:62164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.212.229.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "archresource.co"] [uri "/archive.php"] [unique_id "ajCy2spsKyvb75pkSvagwQAAAgs"]
[Mon Jun 15 20:20:10.543371 2026] [security2:error] [pid 53359:tid 53582] [client 185.246.190.83:59622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.190.246.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jalanbuilders.com"] [uri "/altitude/xmlrpc.php"] [unique_id "ajCy2vC2Xs1VMQlhsgbBcQAAAms"]
[Mon Jun 15 20:20:10.543493 2026] [security2:error] [pid 53359:tid 53582] [client 185.246.190.83:59622] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jalanbuilders.com"] [uri "/altitude/xmlrpc.php"] [unique_id "ajCy2vC2Xs1VMQlhsgbBcQAAAms"]
[Mon Jun 15 20:20:10.611856 2026] [security2:error] [pid 53359:tid 53518] [client 103.125.146.74:34117] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/images/wlw/config.php"] [unique_id "ajCy2vC2Xs1VMQlhsgbBcgAAAis"]
[Mon Jun 15 20:20:10.835442 2026] [security2:error] [pid 53359:tid 53554] [client 64.176.38.237:60416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.38.176.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelgrandpalacecbe.com"] [uri "/goods.php"] [unique_id "ajCy2vC2Xs1VMQlhsgbBeQAAAk8"]
[Mon Jun 15 20:20:11.001022 2026] [security2:error] [pid 53359:tid 53561] [client 103.125.146.56:25763] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sahilpatro.com"] [uri "/wp-includes/lib.php"] [unique_id "ajCy2_C2Xs1VMQlhsgbBfgAAAlY"]
[Mon Jun 15 20:20:11.021935 2026] [security2:error] [pid 51003:tid 51160] [client 69.158.62.169:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kthemani.com"] [uri "/index.php"] [unique_id "ajCy2cpsKyvb75pkSvagnwABqg8"]
[Mon Jun 15 20:20:11.100676 2026] [security2:error] [pid 51003:tid 51084] [remote 57.141.14.6:26286] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fifthestate.agency"] [uri "/index.php"] [unique_id "ajCy2spsKyvb75pkSvagzgACAVA"]